Lucene search

K
cvelistElasticCVELIST:CVE-2018-17245
HistoryDec 20, 2018 - 10:00 p.m.

CVE-2018-17245

2018-12-2022:00:00
CWE-201
elastic
www.cve.org
4

AI Score

9.3

Confidence

High

EPSS

0.002

Percentile

64.7%

Kibana versions 4.0 to 4.6, 5.0 to 5.6.12, and 6.0 to 6.4.2 contain an error in the way authorization credentials are used when generating PDF reports. If a report requests external resources plaintext credentials are included in the HTTP request that could be recovered by an external resource provider.

CNA Affected

[
  {
    "product": "Kibana",
    "vendor": "Elastic",
    "versions": [
      {
        "status": "affected",
        "version": "4.0 to 4.6, 5.0 to 5.6.12, and 6.0 to 6.4.2"
      }
    ]
  }
]

AI Score

9.3

Confidence

High

EPSS

0.002

Percentile

64.7%