Kibana before 4.5.4 and 4.1.11 when a custom output is configured for logging in, cookies and authorization headers could be written to the log files. This information could be used to hijack sessions of other users when using Kibana behind some form of authentication such as Shield.
References
Link | Resource |
---|---|
http://www.securityfocus.com/bid/99178 | Third Party Advisory VDB Entry |
https://www.elastic.co/community/security | Vendor Advisory |
http://www.securityfocus.com/bid/99178 | Third Party Advisory VDB Entry |
https://www.elastic.co/community/security | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
21 Nov 2024, 02:43
Type | Values Removed | Values Added |
---|---|---|
References | () http://www.securityfocus.com/bid/99178 - Third Party Advisory, VDB Entry | |
References | () https://www.elastic.co/community/security - Vendor Advisory |
Information
Published : 2017-06-16 21:29
Updated : 2024-11-21 02:43
NVD link : CVE-2016-1000219
Mitre link : CVE-2016-1000219
CVE.ORG link : CVE-2016-1000219
JSON object : View
Products Affected
elastic
- kibana
CWE
CWE-285
Improper Authorization