CVE-2016-10364

With X-Pack installed, Kibana versions 5.0.0 and 5.0.1 were not properly authenticating requests to advanced settings and the short URL service, any authenticated user could make requests to those services regardless of their own permissions.
References
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:elastic:kibana:5.0.0:*:*:*:*:*:*:*
cpe:2.3:a:elastic:kibana:5.0.1:*:*:*:*:*:*:*

History

21 Nov 2024, 02:43

Type Values Removed Values Added
References () https://www.elastic.co/community/security - Vendor Advisory () https://www.elastic.co/community/security - Vendor Advisory

Information

Published : 2017-06-16 21:29

Updated : 2024-11-21 02:43


NVD link : CVE-2016-10364

Mitre link : CVE-2016-10364

CVE.ORG link : CVE-2016-10364


JSON object : View

Products Affected

elastic

  • kibana
CWE
CWE-306

Missing Authentication for Critical Function

CWE-264

Permissions, Privileges, and Access Controls