CVE-2017-11482

Severity CVSS v4.0:
Pending analysis
Type:
CWE-601 URL Redirection to Untrusted Site ('Open Redirect')
Publication date:
08/12/2017
Last modified:
20/04/2025

Description

The Kibana fix for CVE-2017-8451 was found to be incomplete. With X-Pack installed, Kibana versions before 6.0.1 and 5.6.5 have an open redirect vulnerability on the login page that would enable an attacker to craft a link that redirects to an arbitrary website.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:elastic:kibana:5.6.0:*:*:*:*:*:*:*
cpe:2.3:a:elastic:kibana:5.6.1:*:*:*:*:*:*:*
cpe:2.3:a:elastic:kibana:5.6.2:*:*:*:*:*:*:*
cpe:2.3:a:elastic:kibana:5.6.3:*:*:*:*:*:*:*
cpe:2.3:a:elastic:kibana:5.6.4:*:*:*:*:*:*:*
cpe:2.3:a:elastic:kibana:6.0.0:*:*:*:*:*:*:*
cpe:2.3:a:elastic:kibana:6.0.0:alpha1:*:*:*:*:*:*
cpe:2.3:a:elastic:kibana:6.0.0:alpha2:*:*:*:*:*:*
cpe:2.3:a:elastic:kibana:6.0.0:beta1:*:*:*:*:*:*
cpe:2.3:a:elastic:kibana:6.0.0:beta2:*:*:*:*:*:*
cpe:2.3:a:elastic:kibana:6.0.0:rc1:*:*:*:*:*:*
cpe:2.3:a:elastic:kibana:6.0.0:rc2:*:*:*:*:*:*