6.5
CVSSv3

CVE-2017-8443

Published: 30/06/2017 Updated: 19/10/2020
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 6.5 | Impact Score: 3.6 | Exploitability Score: 2.8
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:P/I:N/A:N

Vulnerability Summary

In Kibana X-Pack security versions before 5.4.3 if a Kibana user opens a crafted Kibana URL the result could be a redirect to an improperly initialized Kibana login screen. If the user enters credentials on this screen, the credentials will appear in the URL bar. The credentials could then be viewed by untrusted parties or logged into the Kibana access logs.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

elastic kibana

Vendor Advisories

In Kibana X-Pack security versions prior to 543 if a Kibana user opens a crafted Kibana URL the result could be a redirect to an improperly initialized Kibana login screen If the user enters credentials on this screen, the credentials will appear in the URL bar The credentials could then be viewed by untrusted parties or logged into the Kibana ...