CVE-2018-17245: Elastic Kibana
Critical severity, CVSS 9.8. EPSS: 1.5% chance of exploitation in the next 30 days.
Kibana versions 4.0 to 4.6, 5.0 to 5.6.12, and 6.0 to 6.4.2 contain an error in the way authorization credentials are used when generating PDF reports. If a report requests external resources plaintext credentials are included in the HTTP request that could be recovered by an external resource provider.
Affected products
- Elastic Kibana: from 4.0.0, up to and including 4.6.0; from 5.0.0, up to and including 5.6.12; from 6.0.0, up to and including 6.4.2
Published 2018-12-20. Last modified 2026-06-17.