Open Redirect Vulnerability in Kibana by Elastic
CVE-2021-22141
6.1MEDIUM
Summary
An open redirect vulnerability exists in Kibana, allowing a logged-in user to be redirected to arbitrary external websites after accessing a specially crafted URL. This issue affects Kibana versions prior to 7.13.0 and 6.8.16, presenting a risk of phishing attacks, as attackers could leverage this flaw to mislead users into visiting malicious sites.
Affected Version(s)
Kibana All versions of Kibana before 7.13.0 and 6.8.16.
References
CVSS V3.1
Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved