Vulnerabilities > Elastic > Kibana > 5.2.2

DATE CVE VULNERABILITY TITLE RISK
2019-03-25 CVE-2019-7609 Code Injection vulnerability in multiple products
Kibana versions before 5.6.15 and 6.6.1 contain an arbitrary code execution flaw in the Timelion visualizer.
network
low complexity
elastic redhat CWE-94
critical
10.0
2019-03-25 CVE-2019-7608 Cross-site Scripting vulnerability in Elastic Kibana
Kibana versions before 5.6.15 and 6.6.1 had a cross-site scripting (XSS) vulnerability that could allow an attacker to obtain sensitive information from or perform destructive actions on behalf of other Kibana users.
network
low complexity
elastic CWE-79
6.1
2018-12-20 CVE-2018-17246 Inclusion of Functionality from Untrusted Control Sphere vulnerability in multiple products
Kibana versions before 6.4.3 and 5.6.13 contain an arbitrary file inclusion flaw in the Console plugin.
network
low complexity
elastic redhat CWE-829
critical
9.8
2018-12-20 CVE-2018-17245 Insufficiently Protected Credentials vulnerability in Elastic Kibana
Kibana versions 4.0 to 4.6, 5.0 to 5.6.12, and 6.0 to 6.4.2 contain an error in the way authorization credentials are used when generating PDF reports.
network
low complexity
elastic CWE-522
critical
9.8
2018-03-30 CVE-2018-3821 Cross-site Scripting vulnerability in Elastic Kibana
Kibana versions after 5.1.1 and before 5.6.7 and 6.1.3 had a cross-site scripting (XSS) vulnerability in the tag cloud visualization that could allow an attacker to obtain sensitive information from or perform destructive actions on behalf of other Kibana users.
network
low complexity
elastic CWE-79
6.1
2018-03-30 CVE-2018-3819 Open Redirect vulnerability in Elastic Kibana
The fix in Kibana for ESA-2017-23 was incomplete.
network
low complexity
elastic CWE-601
6.1
2018-03-30 CVE-2018-3818 Cross-site Scripting vulnerability in Elastic Kibana
Kibana versions 5.1.1 to 6.1.2 and 5.6.6 had a cross-site scripting (XSS) vulnerability via the colored fields formatter that could allow an attacker to obtain sensitive information from or perform destructive actions on behalf of other Kibana users.
network
low complexity
elastic CWE-79
6.1
2017-09-29 CVE-2017-11479 Cross-site Scripting vulnerability in multiple products
Kibana versions prior to 5.6.1 had a cross-site scripting (XSS) vulnerability in Timelion that could allow an attacker to obtain sensitive information from or perform destructive actions on behalf of other Kibana users.
network
low complexity
elasticsearch elastic CWE-79
6.1
2017-06-30 CVE-2017-8443 Information Exposure vulnerability in Elastic Kibana
In Kibana X-Pack security versions prior to 5.4.3 if a Kibana user opens a crafted Kibana URL the result could be a redirect to an improperly initialized Kibana login screen.
network
low complexity
elastic CWE-200
6.5
2017-06-16 CVE-2017-8451 Open Redirect vulnerability in Elastic Kibana
With X-Pack installed, Kibana versions before 5.3.1 have an open redirect vulnerability on the login page that would enable an attacker to craft a link that redirects to an arbitrary website.
network
low complexity
elastic CWE-601
6.1