Summary:
Kibana versions 4.0.0, 4.0.1 and 4.0.2 are vulnerable to a cross-site scripting (XSS) attack. The attack allows execution of arbitrary JavaScript in the context of the user’s browser.
We have been assigned CVE-2015-4093 for this issue.
Fixed versions:
Version 4.0.3 has addressed the vulnerability. Read the release blog post here.
Remediation:
Users running with Kibana 4.0.0-4.0.2 should upgrade to 4.0.3. This will address the vulnerability.