← back
CVE-2018-3819

CVE-2018-3819

EPSS 0.9%CWE-601
The fix in Kibana for ESA-2017-23 was incomplete. With X-Pack security enabled, Kibana versions before 6.1.3 and 5.6.7 have an open redirect vulnerability on the login page that would enable an attacker to craft a link that redirects to an arbitrary website.
Affected products
Elastic · Kibana

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →