# Elastic Stack 7.13.0 and 6.8.16 Security Update

**URL:** <https://discuss.elastic.co/t/elastic-stack-7-13-0-and-6-8-16-security-update/273964>\
**Category:** Security Announcements\
**Created:** [May 25, 2021, 3:17pm UTC](https://discuss.elastic.co/t/elastic-stack-7-13-0-and-6-8-16-security-update/273964 "2021-05-25T15:17:06Z")\
**Posts on this page:** 1\
**Showing post:** 1

<div class="post-metadata">

**Author:** ![douglasday](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/douglasday/32/74044_2.png) [@douglasday](https://discuss.elastic.co/u/douglasday)\
**Post date:** [May 25, 2021, 3:17pm UTC](https://discuss.elastic.co/t/elastic-stack-7-13-0-and-6-8-16-security-update/273964/1 "2021-05-25T15:17:07Z")

</div>

**Kibana url redirection flaw (ESA-2021-12)**

An open redirect flaw was found in Kibana versions before 7.13.0 and 6.8.16. If a logged in user visits a maliciously crafted URL, it could result in Kibana redirecting the user to an arbitrary website.

**Affected Versions:**

All versions of Kibana before 7.13.0 and 6.8.16.

**Solutions and Mitigations:**

Users should update their version of Kibana to 7.13.0 or 6.8.16.

**CVSSv3 - 4.3:** AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N

**CVE ID: CVE-2021-22141**

**CWE-601: URL Redirection to Untrusted Site ('Open Redirect')**

* * *

**Kibana Reporting vulnerabilities (ESA-2021-13)**

Kibana contains an embedded version of the Chromium browser that the Reporting feature uses to generate the downloadable reports. If a user with permissions to generate reports is able to render arbitrary HTML with this browser, they may be able to leverage known Chromium vulnerabilities to conduct further attacks. Kibana contains a number of protections to prevent this browser from rendering arbitrary content.

**Affected Versions:**

All versions of Kibana after 7.0.0 and before 7.13.0

**Solutions and Mitigations:**

Users should update their version of Kibana to 7.13.0

**CVSSv3 - 6.6:** AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H

**CVE ID: CVE-2021-22142**

**CWE-1104: Use of Unmaintained Third Party Components**

---

_[View the full topic](https://discuss.elastic.co/t/elastic-stack-7-13-0-and-6-8-16-security-update/273964)._
