[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
Kibana vulnerability CVE-2015-4093
- To: bugtraq@xxxxxxxxxxxxxxxxx
- Subject: Kibana vulnerability CVE-2015-4093
- From: Kevin Kluge <kevin@xxxxxxxxxx>
- Date: Tue, 9 Jun 2015 14:32:28 -0700
Summary:
Kibana versions 4.0.0, 4.0.1 and 4.0.2 are vulnerable to a cross-site scripting
(XSS) attack. The attack allows execution of arbitrary JavaScript in the
context of the user’s browser.
We have been assigned CVE-2015-4093 for this issue.
Fixed versions:
Versions 4.0.3 and 4.1.0 have addressed the vulnerability.
Remediation:
Users running with Kibana 4.0.0-4.0.2 should upgrade to 4.0.3. This will
address the vulnerability.
CVSS
Overall CVSS score: 5.4