ZeroHour

CVE-2016-10364

CVSS 3.0
6.5 medium
EPSS
<1%p60
Published
()
Modified
Description

With X-Pack installed, Kibana versions 5.0.0 and 5.0.1 were not properly authenticating requests to advanced settings and the short URL service, any authenticated user could make requests to those services regardless of their own permissions.

Vendors
elastic
Products
kibana
Weakness
CWE-306, CWE-264
Vector
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.