Company
Date Published
Author
Court Ewing
Word count
244
Language
-
Hacker News points
None

Summary

On November 15, 2016, Kibana released versions 5.0.1 and 4.6.3, addressing a security vulnerability in the short URL feature that allowed potential redirects from the Kibana domain to other websites. This vulnerability was identified as ESA-2016-09, thanks to the efforts of the GE Digital Security Team. Alongside the security fix, Kibana 5.0.1 included several bug fixes: an updated error message for when sessionStorage is disabled, improved basePath configuration handling when trailing slashes are removed, proper rendering of the Sharing UI in dark theme dashboards, and corrected tile map bounding box filters to prevent errors in Elasticsearch aggregation responses. Users are encouraged to review the release notes and upgrading documentation and to download the latest versions from the Kibana website.