VulnerabilityModified
CVE-2016-1000219
Kibana before 4.5.4 and 4.1.11 when a custom output is configured for logging in, cookies and authorization headers could be written to the log files.
HIGH 7.5EPSS 2.04%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (2.04%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Kibana before 4.5.4 and 4.1.11 when a custom output is configured for logging in, cookies and authorization headers could be written to the log files. This information could be used to hijack sessions of other users when using Kibana behind some form of authentication such as Shield.
- CVSS 3.0
- 7.5 HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
- EPSS
- 2.04% probability · 80th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-285
- Affected
- elastic/kibana
- Source
- cve@mitre.org
References
- http://www.securityfocus.com/bid/99178Third Party Advisory, VDB Entry
- https://www.elastic.co/community/securityVendor Advisory
- http://www.securityfocus.com/bid/99178Third Party Advisory, VDB Entry
- https://www.elastic.co/community/securityVendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.