In Kibana X-Pack security versions prior to 5.4.3 if a Kibana user opens a crafted Kibana URL the result could be a redirect to an improperly initialized Kibana login screen. If the user enters credentials on this screen, the credentials will appear in the URL bar. The credentials could then be viewed by untrusted parties or logged into the Kibana access logs.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: elastic

Published: 2017-06-30T19:00:00

Updated: 2024-08-05T16:34:23.103Z

Reserved: 2017-05-02T00:00:00

Link: CVE-2017-8443

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2017-06-30T19:29:00.180

Modified: 2020-10-19T11:57:16.803

Link: CVE-2017-8443

cve-icon Redhat

Severity : Moderate

Publid Date: 2017-06-30T00:00:00Z

Links: CVE-2017-8443 - Bugzilla