{"id":"CVE-2019-13422","details":"Search Guard Kibana Plugin versions before 5.6.8-7 and before 6.x.y-12 had an issue that an attacker can redirect the user to a potentially malicious site upon Kibana login.","modified":"2026-07-08T16:07:45.796764Z","published":"2019-08-23T14:15:11.547Z","references":[{"type":"ADVISORY","url":"https://docs.search-guard.com/6.x-25/changelog-kibana-6.x-12"},{"type":"ADVISORY","url":"https://search-guard.com/cve-advisory/"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/floragunncom/search-guard-kibana-plugin","events":[{"introduced":"0"},{"fixed":"16390a8509695ce21f861b26a40fd33578e8841e"},{"introduced":"8321d2807120b4dd12f10ef83ff4ec94c90873ac"},{"fixed":"0dfdfa6ad5a2ea3a4896514250594bb5e5655354"}],"database_specific":{"source":"CPE_RANGE","cpe":"cpe:2.3:a:search-guard:search_guard:*:*:*:*:*:kibana:*:*","extracted_events":[{"introduced":"0"},{"fixed":"5.6.8-7"},{"introduced":"6.1.0-8"},{"fixed":"6.2.3-12"}]}}],"versions":["v5.6.8-6","v6.2.2-10","v5.6.7-6","v5.6.6-5","v5.6.5-5","v6.1.0-8","v5.6.4-5","v5.6.0-4","v5.6.3-4","v5.6.2-4","v5.5.2-4","v5.5.1-4","v5.5.1-3","v5.5.0-3","v5.4.1-3","v5.4.3-3","v5.4.3","v5.4.2-3","v5.3.2-2","v5.4.0","v5.3.1-2","v1"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2019-13422.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"}]}