An open redirect issue was discovered in Kibana that could lead to a user being redirected to an arbitrary website if they use a maliciously crafted Kibana URL.
The web application accepts a user-controlled input that specifies a link to an external site, and uses that link in a redirect.
Link | Tags |
---|---|
https://www.elastic.co/community/security | vendor advisory |
https://discuss.elastic.co/t/kibana-7-17-9-and-8-6-2-security-update/325782 | release notes vendor advisory |