|
266671
|
6.1 |
MEDIUM
Network
|
elastic
|
kibana
|
Kibana versions after and including 4.3 and before 4.6.2 are vulnerable to a cross-site scripting (XSS) attack.
|
CWE-79
Cross-site Scripting
|
CVE-2016-10366
|
2024-11-21 11:43 |
2017-06-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266672
|
6.1 |
MEDIUM
Network
|
elastic
|
kibana
|
Kibana versions before 4.6.3 and 5.0.1 have an open redirect vulnerability that would enable an attacker to craft a link in the Kibana domain that redirects to an arbitrary website.
|
CWE-601
Open Redirect
|
CVE-2016-10365
|
2024-11-21 11:43 |
2017-06-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266673
|
6.5 |
MEDIUM
Network
|
elastic
|
kibana
|
With X-Pack installed, Kibana versions 5.0.0 and 5.0.1 were not properly authenticating requests to advanced settings and the short URL service, any authenticated user could make requests to those se…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2016-10364
|
2024-11-21 11:43 |
2017-06-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266674
|
7.5 |
HIGH
Network
|
elastic
|
logstash
|
Logstash versions prior to 2.3.3, when using the Netflow Codec plugin, a remote attacker crafting malicious Netflow v5, Netflow v9 or IPFIX packets could perform a denial of service attack on the Log…
|
CWE-404
Improper Resource Shutdown or Release
|
CVE-2016-10363
|
2024-11-21 11:43 |
2017-06-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266675
|
6.5 |
MEDIUM
Network
|
elasticsearch
|
output_plugin
|
Prior to Logstash version 5.0.1, Elasticsearch Output plugin when updating connections after sniffing, would log to file HTTP basic auth credentials.
|
CWE-200
Information Exposure
|
CVE-2016-10362
|
2024-11-21 11:43 |
2017-06-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266676
|
7.5 |
HIGH
Network
|
elastic
|
logstash
|
Logstash prior to version 2.1.2, the CSV output can be attacked via engineered input that will create malicious formulas in the CSV data.
|
CWE-88
Argument Injection
|
CVE-2016-1000222
|
2024-11-21 11:43 |
2017-06-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266677
|
7.5 |
HIGH
Network
|
elastic
|
logstash
|
Logstash prior to version 2.3.4, Elasticsearch Output plugin would log to file HTTP authorization headers which could contain sensitive information.
|
CWE-200
Information Exposure
|
CVE-2016-1000221
|
2024-11-21 11:43 |
2017-06-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266678
|
6.1 |
MEDIUM
Network
|
elastic
|
kibana
|
Kibana before 4.5.4 and 4.1.11 are vulnerable to an XSS attack that would allow an attacker to execute arbitrary JavaScript in users' browsers.
|
CWE-79
Cross-site Scripting
|
CVE-2016-1000220
|
2024-11-21 11:43 |
2017-06-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266679
|
7.5 |
HIGH
Network
|
elastic
|
kibana
|
Kibana before 4.5.4 and 4.1.11 when a custom output is configured for logging in, cookies and authorization headers could be written to the log files. This information could be used to hijack session…
|
CWE-285
Improper Authorization
|
CVE-2016-1000219
|
2024-11-21 11:43 |
2017-06-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266680
|
8.8 |
HIGH
Network
|
elastic
|
kibana_reporting
|
Kibana Reporting plugin version 2.4.0 is vulnerable to a CSRF vulnerability that could allow an attacker to generate superfluous reports whenever an authenticated Kibana user navigates to a specially…
|
CWE-352
Origin Validation Error
|
CVE-2016-1000218
|
2024-11-21 11:43 |
2017-06-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|