|
|
Log in / Subscribe / Register

kibana: two vulnerabilties

Package(s):Kibana CVE #(s):
Created:September 8, 2016 Updated:September 8, 2016
Description: From the Red Hat advisory:

* A flaw was found in Kibana's logging functionality. If custom logging output was configured in Kibana, private user data could be written to the Kibana log files. A system attacker could use this data to hijack sessions of other users when using Kibana behind some form of authentication such as Shield.

* A cross-site scripting (XSS) flaw was found in Kibana. A remote attacker could use this flaw to inject arbitrary web script into pages served to other users.

Alerts:
Red Hat RHSA-2016:1836-01 Kibana 2016-09-08

to post comments


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds