# Kibana Cross-site Request Forgery CVE-2015-8131

**URL:** https://discuss.elastic.co/t/kibana-cross-site-request-forgery-cve-2015-8131/35002
**Category:** Security Announcements
**Created:** [November 18, 2015, 10:46pm UTC](https://discuss.elastic.co/t/kibana-cross-site-request-forgery-cve-2015-8131/35002 "2015-11-18T22:46:49Z")
**Posts on this page:** 1
**Showing post:** 1

<div class="post-metadata">

### Author: ![KevinKluge](https://avatars.discourse-cdn.com/v4/letter/k/dfb087/32.png) [@KevinKluge](https://discuss.elastic.co/u/KevinKluge)
#### Post date: [November 18, 2015, 10:46pm UTC](https://discuss.elastic.co/t/kibana-cross-site-request-forgery-cve-2015-8131/35002/1 "2015-11-18T22:46:50Z")

</div>

CVE: CVE-2015-8131  
Affected versions: All versions up to and including 4.1.2 and 4.2.0.

The vulnerability is a cross-site request forgery (CSRF or XSRF) that could allow an attacker to read and write changes to the .kibana index or gain read and write access to Kibana plugin actions.

Remediation: All users should upgrade to Kibana 4.2.1 or 4.1.3.

While the attack vector can be lessened or eliminated with certain authentication setups, we urge all users to upgrade in any case.

CVSS Score: 6.1

We would like to thank Ruben van Vreeland for reporting the issue and working with us on the resolution.

Related links:

> **[Kibana 4.2.1 and 4.1.3 released
	  	 | Elastic](https://www.elastic.co/blog/kibana-4-2-1-and-4-1-3)**
>
> Today we're releasing stability and security updates to Kibana 4.1 and 4.2. The 4.2.x series requires Elasticsearch 2.0+, while the 4.1.x series supports Elasticsearch 1.4.4 - 1.7. ...

---

_[View the full topic](https://discuss.elastic.co/t/kibana-cross-site-request-forgery-cve-2015-8131/35002)._
