# Kibana 5.0.1 and 4.6.3 released with a fix for an open redirect vulnerability

**URL:** <https://discuss.elastic.co/t/kibana-5-0-1-and-4-6-3-released-with-a-fix-for-an-open-redirect-vulnerability/66142>\
**Category:** Security Announcements\
**Created:** [November 15, 2016, 6:13pm UTC](https://discuss.elastic.co/t/kibana-5-0-1-and-4-6-3-released-with-a-fix-for-an-open-redirect-vulnerability/66142 "2016-11-15T18:13:19Z")\
**Posts on this page:** 1\
**Showing post:** 1

<div class="post-metadata">

**Author:** ![Court](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/court/32/6640_2.png) [@Court](https://discuss.elastic.co/u/Court)\
**Post date:** [November 15, 2016, 6:13pm UTC](https://discuss.elastic.co/t/kibana-5-0-1-and-4-6-3-released-with-a-fix-for-an-open-redirect-vulnerability/66142/1 "2016-11-15T18:13:19Z")

</div>

Kibana versions 5.0.1 and 4.6.3 fix an open redirect vulnerability in the short URL feature that would allow an attacker to create a redirect from the Kibana domain to a different website. We’ve assigned this vulnerability the identifier ESA-2016-08. Thank you to the GE Digital Security Team for finding and reporting the issue.

Users are encouraged to upgrade to Kibana 5.0.1 or 4.6.3 as soon as possible.

As always, grab the latest release from our [downloads](https://www.elastic.co/downloads/kibana) page.

For more information about this release, check out the [blog post](https://www.elastic.co/blog/kibana-5-0-1-and-4-6-3-released) or [release notes](https://www.elastic.co/guide/en/kibana/current/release-notes-5.0.1.html).

---

_[View the full topic](https://discuss.elastic.co/t/kibana-5-0-1-and-4-6-3-released-with-a-fix-for-an-open-redirect-vulnerability/66142)._
