CVE-2018-17245

Severity CVSS v4.0:
Pending analysis
Type:
CWE-522 Insufficiently Protected Credentials
Publication date:
20/12/2018
Last modified:
14/08/2020

Description

Kibana versions 4.0 to 4.6, 5.0 to 5.6.12, and 6.0 to 6.4.2 contain an error in the way authorization credentials are used when generating PDF reports. If a report requests external resources plaintext credentials are included in the HTTP request that could be recovered by an external resource provider.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:elastic:kibana:*:*:*:*:*:*:*:* 4.0.0 (including) 4.6.0 (including)
cpe:2.3:a:elastic:kibana:*:*:*:*:*:*:*:* 5.0.0 (including) 5.6.12 (including)
cpe:2.3:a:elastic:kibana:*:*:*:*:*:*:*:* 6.0.0 (including) 6.4.2 (including)