URL redirection to an untrusted site ('Open Redirect') in Kibana can lead to sending a user to an arbitrary site and server-side request forgery via a specially crafted URL.
| Software | From | Fixed in |
|---|---|---|
| elastic / kibana | 7.0.0 | 7.17.29 |
| elastic / kibana | 8.0.0 | 8.17.8 |
| elastic / kibana | 8.18.0 | 8.18.3 |
| elastic / kibana | 9.0.0 | 9.0.3 |