Vulnerabilities > Elastic > Kibana > 0.20.0
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2019-03-25 | CVE-2019-7610 | Command Injection vulnerability in Elastic Kibana Kibana versions before 6.6.1 contain an arbitrary code execution flaw in the security audit logger. | 9.0 |
2019-03-25 | CVE-2019-7609 | Code Injection vulnerability in multiple products Kibana versions before 5.6.15 and 6.6.1 contain an arbitrary code execution flaw in the Timelion visualizer. | 10.0 |
2019-03-25 | CVE-2019-7608 | Cross-site Scripting vulnerability in Elastic Kibana Kibana versions before 5.6.15 and 6.6.1 had a cross-site scripting (XSS) vulnerability that could allow an attacker to obtain sensitive information from or perform destructive actions on behalf of other Kibana users. | 6.1 |
2018-03-30 | CVE-2018-3819 | Open Redirect vulnerability in Elastic Kibana The fix in Kibana for ESA-2017-23 was incomplete. | 6.1 |
2017-06-30 | CVE-2017-8443 | Information Exposure vulnerability in Elastic Kibana In Kibana X-Pack security versions prior to 5.4.3 if a Kibana user opens a crafted Kibana URL the result could be a redirect to an improperly initialized Kibana login screen. | 6.5 |
2017-06-16 | CVE-2017-8452 | Uncontrolled File Descriptor Consumption vulnerability in Elastic Kibana Kibana versions prior to 5.2.1 configured for SSL client access, file descriptors will fail to be cleaned up after certain requests and will accumulate over time until the process crashes. | 7.5 |
2017-06-16 | CVE-2017-8451 | Open Redirect vulnerability in Elastic Kibana With X-Pack installed, Kibana versions before 5.3.1 have an open redirect vulnerability on the login page that would enable an attacker to craft a link that redirects to an arbitrary website. | 6.1 |
2017-06-16 | CVE-2016-10365 | Open Redirect vulnerability in Elastic Kibana Kibana versions before 4.6.3 and 5.0.1 have an open redirect vulnerability that would enable an attacker to craft a link in the Kibana domain that redirects to an arbitrary website. | 6.1 |