CVE-2016-10364

With X-Pack installed, Kibana versions 5.0.0 and 5.0.1 were not properly authenticating requests to advanced settings and the short URL service, any authenticated user could make requests to those services regardless of their own permissions.
References
Link Resource
https://www.elastic.co/community/security Vendor Advisory
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

OR cpe:2.3:a:elastic:kibana:5.0.1:*:*:*:*:*:*:*
cpe:2.3:a:elastic:kibana:5.0.0:*:*:*:*:*:*:*

Information

Published : 2017-06-16 14:29

Updated : 2020-08-14 10:30


NVD link : CVE-2016-10364

Mitre link : CVE-2016-10364


JSON object : View

CWE
CWE-264

Permissions, Privileges, and Access Controls

Advertisement

dedicated server usa

Products Affected

elastic

  • kibana