# Kibana 5.5.2 and 4.6.5 security update

**URL:** <https://discuss.elastic.co/t/kibana-5-5-2-and-4-6-5-security-update/97462>\
**Category:** Security Announcements\
**Created:** [August 17, 2017, 5:32pm UTC](https://discuss.elastic.co/t/kibana-5-5-2-and-4-6-5-security-update/97462 "2017-08-17T17:32:58Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![joshbressers](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/joshbressers/32/42332_2.png) [@joshbressers](https://discuss.elastic.co/u/joshbressers)\
**Post date:** [August 17, 2017, 5:32pm UTC](https://discuss.elastic.co/t/kibana-5-5-2-and-4-6-5-security-update/97462/1 "2017-08-17T17:32:58Z")

</div>

**Kibana markdown parser Cross Site Scripting (XSS) error (ESA-2017-16)**

Kibana versions prior to 5.5.2 had a cross-site scripting (XSS) vulnerability in the markdown parser that could allow an attacker to obtain sensitive information from or perform destructive actions on behalf of other Kibana users.

**Affected Versions:** All prior to 5.5.2 and 4.6.5

**Solutions and Mitigations:**  
Users should upgrade to Kibana version 5.5.2 or 4.6.5.

* * *

**Reporting impersonation error (ESA-2017-17)**

The Reporting feature in X-Pack in versions prior to 5.5.2 and standalone Reporting plugin versions versions prior to 2.4.6 had an impersonation vulnerability. A user with the reporting\_user role could execute a report with the permissions of another reporting user, possibly gaining access to sensitive data.

**Affected Versions:** All prior to 5.5.2 and 2.4.6

**Solutions and Mitigations:**  
Reporting users should upgrade to X-Pack version 5.5.2 or Reporting Plugin version 2.4.6. A mitigation for this issue is to remove the reporting\_user role from any untrusted users of your Elastic Stack.

**CVE ID:** CVE-2017-8446

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 4, 2022, 4:55am UTC](https://discuss.elastic.co/t/kibana-5-5-2-and-4-6-5-security-update/97462/2 "2022-11-04T04:55:58Z")

</div>


