Back to Database
Status published
Medium
CVE-2019-13422
Search Guard Kibana Plugin versions before 5.6.8-7 and before 6.x.y-12...
Vulnerability Description
Search Guard Kibana Plugin versions before 5.6.8-7 and before 6.x.y-12 had an issue that an attacker can redirect the user to a potentially malicious site upon Kibana login.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2019-13422
Credits & Attribution
No credits recorded in the NVD database.
References
More from floragunn
View All →CVE-2025-13653
Unauthorized access to documents in data streams with specially crafted requests
Medium
4.3
CVE-2025-12149
Unauthorized access to documents protected by Document-Level Security (DLS), when Signals watches include a search query involving protected documents
Medium
6
CVE-2025-12148
Unauthorized access to fields protected by Field Masking (FM) for fields of type IP
Medium
6
CVE-2025-12147
Unauthorized access to fields protected by Field-Level Security (FLS) when those fields are members of an object
Medium
6
CVE-2019-13423
Search Guard Kibana Plugin versions before 5.6.8-7 and before 6.x.y-12...
High
8.8
Affected Vendor
floragunn
View all reports →Affected Software
Search Guard Kibana Plugin
Vulnerable Versions:
unspecified
Timeline
Official Publish:
August 23rd, 2019
Last Modified:
August 4th, 2024
Added to House:
July 20th, 2026
CVSS Vectors
V3:
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
MITRE ATT&CK TTPs
T1566
Phishing
Initial Access
T1204
User Execution
Execution
T1071
Application Layer Protocol
Command and Control
T1189
Drive-by Compromise
Initial Access
T1036
Masquerading
Defense Evasion
T1059.007
JavaScript
Execution
T1539
Steal Web Session Cookie
Collection
T1213
Data from Information Repositories
Collection
T1567
Exfiltration Over Web Service
Exfiltration
T1491.001
Defacement
Impact