CVE-2018-20698: Search-Guard Search Guard

Medium severity, CVSS 6.1. EPSS: 0.8% chance of exploitation in the next 30 days.

The floragunn Search Guard plugin before 6.x-16 for Kibana allows URL injection for login redirects on the login page when basePath is set.

Affected products

  • Search-Guard Search Guard: before 6.3.0-16 (fixed in 6.3.0-16)

Published 2019-04-09. Last modified 2026-06-17.