# Kibana prone to CSRF Attack

**URL:** <https://discuss.elastic.co/t/kibana-prone-to-csrf-attack/245873>\
**Category:** Kibana\
**Created:** [August 21, 2020, 7:59am UTC](https://discuss.elastic.co/t/kibana-prone-to-csrf-attack/245873 "2020-08-21T07:59:42Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![robinhood\_lko](https://avatars.discourse-cdn.com/v4/letter/r/5f8ce5/32.png) [@robinhood\_lko](https://discuss.elastic.co/u/robinhood_lko)\
**Post date:** [August 21, 2020, 7:59am UTC](https://discuss.elastic.co/t/kibana-prone-to-csrf-attack/245873/1 "2020-08-21T07:59:42Z")

</div>

Dear Team,

Security team has raised a flag that Kibana is prone to CSRF attack . We have deployed latest version of ECK Components. Please can you guide me if there is any settings which can help to fix this.

ECK 1.1.2  
Elastic 7.8.0  
Kibana 7.8.0

I was under impression that this vulnerability was fixed in Kiaban 5.x+ versions.

Please help.

Thanks.

---

<div class="post-metadata">

**Author:** ![Emanuil](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/emanuil/32/36783_2.png) [@Emanuil](https://discuss.elastic.co/u/Emanuil)\
**Post date:** [August 21, 2020, 6:49pm UTC](https://discuss.elastic.co/t/kibana-prone-to-csrf-attack/245873/2 "2020-08-21T18:49:56Z")

</div>

Any more details from your security team on the vulnerability they've detected? If they saw it manually, what pages and elements were they looking at? Or if an automatic tool flagged Kibana as vulnerable, can you provide the output of the tool?

Send these details to [Security issues | Elastic](https://www.elastic.co/community/security) rather than posting the answers here.

> I was under impression that this vulnerability was fixed in Kiaban 5.x+ versions.

That's still correct, the last known CSRF vulnerability isn't present in Kibana 5 or above. List of public vulnerabilities: [Elasticsearch Kibana : Security vulnerabilities, CVEs](https://www.cvedetails.com/vulnerability-list/vendor_id-13554/product_id-31867/Elasticsearch-Kibana.html) . So if there is no mistake and your team has detected a new one, please have them send details to that page ^ ASAP, your report would be much appreciated.

---

<div class="post-metadata">

**Author:** ![robinhood\_lko](https://avatars.discourse-cdn.com/v4/letter/r/5f8ce5/32.png) [@robinhood\_lko](https://discuss.elastic.co/u/robinhood_lko)\
**Post date:** [August 24, 2020, 8:53am UTC](https://discuss.elastic.co/t/kibana-prone-to-csrf-attack/245873/3 "2020-08-24T08:53:04Z")

</div>

Hi @Emanuil I have send the data to security but i did not hear back. What will be the best way to follow up on that. Thanks.

---

<div class="post-metadata">

**Author:** ![Emanuil](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/emanuil/32/36783_2.png) [@Emanuil](https://discuss.elastic.co/u/Emanuil)\
**Post date:** [August 24, 2020, 12:19pm UTC](https://discuss.elastic.co/t/kibana-prone-to-csrf-attack/245873/4 "2020-08-24T12:19:53Z")

</div>

Let's move this to direct messages, thanks for reporting. I'll follow up.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 21, 2020, 12:19pm UTC](https://discuss.elastic.co/t/kibana-prone-to-csrf-attack/245873/5 "2020-09-21T12:19:56Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
