CVE-2016-10364
medium
CVSS v3
6.5
CVSS v2
4.0
VIR risk
6.5
Description
With X-Pack installed, Kibana versions 5.0.0 and 5.0.1 were not properly authenticating requests to advanced settings and the short URL service, any authenticated user could make requests to those services regardless of their own permissions.
Predictions
Exploit likelihood
75%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: security@elastic.co — https://www.elastic.co/community/security
References
CWEs
CWE-306 CWE-264
Verify integrity in audit chain (admin only). AS-IS.