Executive Summary

Summary
Title Red Hat OpenShift Enterprise Kibana security update
Informations
Name RHSA-2016:1836 First vendor Publication 2016-09-08
Vendor RedHat Last vendor Modification 2016-09-08
Severity (Vendor) N/A Revision 01

Security-Database Scoring CVSS v3

Cvss vector : N/A
Overall CVSS Score NA
Base Score NA Environmental Score NA
impact SubScore NA Temporal Score NA
Exploitabality Sub Score NA
 
Calculate full CVSS 3.0 Vectors scores

Security-Database Scoring CVSS v2

Cvss vector :
Cvss Base Score N/A Attack Range N/A
Cvss Impact Score N/A Attack Complexity N/A
Cvss Expoit Score N/A Authentication N/A
Calculate full CVSS 2.0 Vectors scores

Detail

Problem Description:

An update for Red Hat OpenShift Enterprise Kibana images is now available.

Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

2. Relevant releases/architectures:

Red Hat OpenShift Enterprise 3.1 - noarch, x86_64 Red Hat OpenShift Enterprise 3.2 - noarch, x86_64

3. Description:

OpenShift Enterprise by Red Hat is the company's cloud computing Platform- as-a-Service (PaaS) solution designed for on-premise or private cloud deployments.

Security Fix(es):

* A flaw was found in Kibana's logging functionality. If custom logging output was configured in Kibana, private user data could be written to the Kibana log files. A system attacker could use this data to hijack sessions of other users when using Kibana behind some form of authentication such as Shield.

* A cross-site scripting (XSS) flaw was found in Kibana. A remote attacker could use this flaw to inject arbitrary web script into pages served to other users.

4. Solution:

Before applying this update, make sure all previously released errata relevant to your system have been applied.

For details on how to apply this update, refer to:

https://access.redhat.com/articles/11258

The following images are included in this errata:

openshift3/logging-kibana:3.1.1-10 openshift3/logging-elasticsearch:3.1.1-14 openshift3/logging-kibana:3.2.1-5 openshift3/logging-elasticsearch:3.2.1-7

5. Bugs fixed (https://bugzilla.redhat.com/):

1364389 - kibana: XSS vulnerability 1364394 - kibana: Session hijack via stealing cookies and auth headers from log

Original Source

Url : https://rhn.redhat.com/errata/RHSA-2016-1836.html

Alert History

If you want to see full details history, please login or register.
0
Date Informations
2016-09-08 21:22:20
  • First insertion