CVE-2016-10364

With X-Pack installed, Kibana versions 5.0.0 and 5.0.1 were not properly authenticating requests to advanced settings and the short URL service, any authenticated user could make requests to those services regardless of their own permissions.
References
Link Resource
https://www.elastic.co/community/security Vendor Advisory
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:elastic:kibana:5.0.0:*:*:*:*:*:*:*
cpe:2.3:a:elastic:kibana:5.0.1:*:*:*:*:*:*:*

History

No history.

Information

Published : 2017-06-16 21:29

Updated : 2024-02-04 19:29


NVD link : CVE-2016-10364

Mitre link : CVE-2016-10364

CVE.ORG link : CVE-2016-10364


JSON object : View

Products Affected

elastic

  • kibana
CWE
CWE-264

Permissions, Privileges, and Access Controls

CWE-306

Missing Authentication for Critical Function