CVE-2018-20698

Severity CVSS v4.0:
Pending analysis
Type:
CWE-601 URL Redirection to Untrusted Site ('Open Redirect')
Publication date:
09/04/2019
Last modified:
24/08/2020

Description

The floragunn Search Guard plugin before 6.x-16 for Kibana allows URL injection for login redirects on the login page when basePath is set.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:search-guard:search_guard:*:*:*:*:*:kibana:*:* 6.3.0-16 (excluding)