Kibana vulnerability CVE-2015-4093

From: Kevin Kluge <kevin@elastic.co>
To: bugtraq@securityfocus.com
Cc:
Subject: Kibana vulnerability CVE-2015-4093
Date:


Summary:
Kibana versions 4.0.0, 4.0.1 and 4.0.2 are vulnerable to a cross-site scripting (XSS) attack.  The attack allows execution of arbitrary JavaScript in the context of the user\u20ac\u2122s browser.

We have been assigned CVE-2015-4093 for this issue.


Fixed versions:
Versions  4.0.3 and 4.1.0 have addressed the vulnerability.


Remediation:
Users running with Kibana 4.0.0-4.0.2 should upgrade to 4.0.3. This will address the vulnerability.


CVSS
Overall CVSS score: 5.4





Copyright © 1995-2018 LinuxRocket.net. All rights reserved.