kibana: two vulnerabilties
| Package(s): | Kibana | CVE #(s): | |||||
| Created: | September 8, 2016 | Updated: | September 8, 2016 | ||||
| Description: | From the Red Hat advisory:
* A flaw was found in Kibana's logging functionality. If custom logging output was configured in Kibana, private user data could be written to the Kibana log files. A system attacker could use this data to hijack sessions of other users when using Kibana behind some form of authentication such as Shield. * A cross-site scripting (XSS) flaw was found in Kibana. A remote attacker could use this flaw to inject arbitrary web script into pages served to other users. | ||||||
| Alerts: |
| ||||||
