VYPR
Medium severity6.1NVD Advisory· Published Jun 16, 2017· Updated May 13, 2026

CVE-2016-10365

CVE-2016-10365

Description

Kibana versions before 4.6.3 and 5.0.1 have an open redirect vulnerability that would enable an attacker to craft a link in the Kibana domain that redirects to an arbitrary website.

Affected products

3
  • Elastic/Kibana3 versions
    cpe:2.3:a:elastic:kibana:*:*:*:*:*:*:*:*+ 2 more
    • cpe:2.3:a:elastic:kibana:*:*:*:*:*:*:*:*range: <=4.6.2
    • cpe:2.3:a:elastic:kibana:*:rc1:*:*:*:*:*:*range: <=5.0.0
    • (no CPE)range: before 5.0.1 and 4.6.3

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.