# Kibana 6.0.1 and 5.6.5 security update

**URL:** <https://discuss.elastic.co/t/kibana-6-0-1-and-5-6-5-security-update/110571>\
**Category:** Security Announcements\
**Created:** [December 6, 2017, 8:06pm UTC](https://discuss.elastic.co/t/kibana-6-0-1-and-5-6-5-security-update/110571 "2017-12-06T20:06:56Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![joshbressers](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/joshbressers/32/42332_2.png) [@joshbressers](https://discuss.elastic.co/u/joshbressers)\
**Post date:** [December 6, 2017, 8:06pm UTC](https://discuss.elastic.co/t/kibana-6-0-1-and-5-6-5-security-update/110571/1 "2017-12-06T20:06:56Z")

</div>

**Kibana cross site scripting issue (ESA-2017-22)**

Kibana versions prior to 6.0.1 and 5.6.5 had a cross-site scripting (XSS) vulnerability via URL fields that could allow an attacker to obtain sensitive information from or perform destructive actions on behalf of other Kibana users.

**Affected Versions:** All prior to 6.0.1 and 5.6.5

**Solutions and Mitigations:**  
Users should upgrade to Kibana version 6.0.1 or 5.6.5. There are no known workarounds for this issue.

**CVE ID:** CVE-2017-11481

* * *

**Kibana open redirect flaw (ESA-2017-23)**

The Kibana fix for CVE-2017-8451 was found to be incomplete. With X-Pack installed, Kibana versions before 6.0.1 and 5.6.5 have an open redirect vulnerability on the login page that would enable an attacker to craft a link that redirects to an arbitrary website.

**Affected Versions:** All prior to 6.0.1 and 5.6.5

**Solutions and Mitigations:**  
Users should upgrade to Kibana version 6.0.1 or 5.6.5. There are no known workarounds for this issue.

**CVE ID:** CVE-2017-11482

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 4, 2022, 5:06am UTC](https://discuss.elastic.co/t/kibana-6-0-1-and-5-6-5-security-update/110571/2 "2022-11-04T05:06:07Z")

</div>


