Vulnerabilities > Elastic > Kibana

DATE CVE VULNERABILITY TITLE RISK
2017-06-16 CVE-2016-1000219 Improper Authorization vulnerability in Elastic Kibana
Kibana before 4.5.4 and 4.1.11 when a custom output is configured for logging in, cookies and authorization headers could be written to the log files.
network
low complexity
elastic CWE-285
5.0
2017-06-16 CVE-2015-9056 Cross-site Scripting vulnerability in Elastic Kibana
Kibana versions prior to 4.1.3 and 4.2.1 are vulnerable to a XSS attack.
network
elastic CWE-79
4.3
2017-06-05 CVE-2017-8440 Cross-site Scripting vulnerability in Elastic Kibana
Starting in version 5.3.0, Kibana had a cross-site scripting (XSS) vulnerability in the Discover page that could allow an attacker to obtain sensitive information from or perform destructive actions on behalf of other Kibana users.
network
elastic CWE-79
4.3
2017-06-05 CVE-2017-8439 Cross-site Scripting vulnerability in Elastic Kibana 5.4.0
Kibana version 5.4.0 was affected by a Cross Site Scripting (XSS) bug in the Time Series Visual Builder.
network
elastic CWE-79
4.3
2015-12-07 CVE-2015-8131 Cross-Site Request Forgery (CSRF) vulnerability in Elastic Kibana
Cross-site request forgery (CSRF) vulnerability in Elasticsearch Kibana before 4.1.3 and 4.2.x before 4.2.1 allows remote attackers to hijack the authentication of unspecified victims via unknown vectors.
network
elastic CWE-352
6.8
2015-06-15 CVE-2015-4093 Cross-site Scripting vulnerability in Elastic Kibana 4.0.0/4.0.1/4.0.2
Cross-site scripting (XSS) vulnerability in Elasticsearch Kibana 4.x before 4.0.3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
network
elastic CWE-79
4.3