CVE-2017-8443 Vulnerability Details

  /     /     /  

CVE-2017-8443 Metadata Quick Info

CVE Published: 30/06/2017 | CVE Updated: 05/08/2024 | CVE Year: 2017
Source: elastic | Vendor: Elastic | Product: Kibana X-Pack Security
Status : PUBLISHED

CVE-2017-8443 Description

In Kibana X-Pack security versions prior to 5.4.3 if a Kibana user opens a crafted Kibana URL the result could be a redirect to an improperly initialized Kibana login screen. If the user enters credentials on this screen, the credentials will appear in the URL bar. The credentials could then be viewed by untrusted parties or logged into the Kibana access logs.

Metrics

CVSS Version: 3.1 | Base Score: n/a
Vector: n/a

l➤ Exploitability Metrics:
    Attack Vector (AV)*
    Attack Complexity (AC)*
    Privileges Required (PR)*
    User Interaction (UI)*
    Scope (S)*

l➤ Impact Metrics:
    Confidentiality Impact (C)*
    Integrity Impact (I)*
    Availability Impact (A)*

Weakness Enumeration (CWE)

CWE-ID: CWE-598
CWE Name: CWE-598: Information Exposure Through Query Strings in GET Request
Source: Elastic

Common Attack Pattern Enumeration and Classification (CAPEC)

CAPEC-ID:
CAPEC Description:


Source: NVD (National Vulnerability Database).