{"api_version":"1","generated_at":"2026-07-23T06:49:49+00:00","cve":"CVE-2016-10364","urls":{"html":"https://cve.report/CVE-2016-10364","api":"https://cve.report/api/cve/CVE-2016-10364.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2016-10364","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2016-10364"},"summary":{"title":"CVE-2016-10364","description":"With X-Pack installed, Kibana versions 5.0.0 and 5.0.1 were not properly authenticating requests to advanced settings and the short URL service, any authenticated user could make requests to those services regardless of their own permissions.","state":"PUBLISHED","assigner":"elastic","published_at":"2017-06-16 21:29:00","updated_at":"2025-04-20 01:37:25"},"problem_types":["CWE-306","CWE-264","CWE-306 CWE-306: Missing Authentication for Critical Function"],"metrics":[{"version":"3.0","source":"nvd@nist.gov","type":"Primary","score":"6.5","severity":"MEDIUM","vector":"CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","data":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"}},{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"4","severity":"","vector":"AV:N/AC:L/Au:S/C:P/I:N/A:N","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:P/I:N/A:N","baseScore":4,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"}}],"references":[{"url":"https://www.elastic.co/community/security","name":"https://www.elastic.co/community/security","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"","mime":"","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2016-10364","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2016-10364","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"Elastic","product":"Elastic X-Pack Security","version":"affected before 5.0.2","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2016","cve_id":"10364","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"elastic","cpe5":"kibana","cpe6":"5.0.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2016","cve_id":"10364","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"elastic","cpe5":"kibana","cpe6":"5.0.1","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-06T03:21:50.862Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"https://www.elastic.co/community/security"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"Elastic X-Pack Security","vendor":"Elastic","versions":[{"status":"affected","version":"before 5.0.2"}]}],"datePublic":"2016-11-29T00:00:00.000Z","descriptions":[{"lang":"en","value":"With X-Pack installed, Kibana versions 5.0.0 and 5.0.1 were not properly authenticating requests to advanced settings and the short URL service, any authenticated user could make requests to those services regardless of their own permissions."}],"problemTypes":[{"descriptions":[{"cweId":"CWE-306","description":"CWE-306: Missing Authentication for Critical Function","lang":"en","type":"CWE"}]}],"providerMetadata":{"dateUpdated":"2017-06-16T20:57:02.000Z","orgId":"271b6943-45a9-4f3a-ab4e-976f3fa05b5a","shortName":"elastic"},"references":[{"tags":["x_refsource_CONFIRM"],"url":"https://www.elastic.co/community/security"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"security@elastic.co","ID":"CVE-2016-10364","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"Elastic X-Pack Security","version":{"version_data":[{"version_value":"before 5.0.2"}]}}]},"vendor_name":"Elastic"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"With X-Pack installed, Kibana versions 5.0.0 and 5.0.1 were not properly authenticating requests to advanced settings and the short URL service, any authenticated user could make requests to those services regardless of their own permissions."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"CWE-306: Missing Authentication for Critical Function"}]}]},"references":{"reference_data":[{"name":"https://www.elastic.co/community/security","refsource":"CONFIRM","url":"https://www.elastic.co/community/security"}]}}}},"cveMetadata":{"assignerOrgId":"271b6943-45a9-4f3a-ab4e-976f3fa05b5a","assignerShortName":"elastic","cveId":"CVE-2016-10364","datePublished":"2017-06-16T21:00:00.000Z","dateReserved":"2017-05-02T00:00:00.000Z","dateUpdated":"2024-08-06T03:21:50.862Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2017-06-16 21:29:00","lastModifiedDate":"2025-04-20 01:37:25","problem_types":["CWE-306","CWE-264","CWE-306 CWE-306: Missing Authentication for Critical Function"],"metrics":{"cvssMetricV30":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":3.6}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:P/I:N/A:N","baseScore":4,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:elastic:kibana:5.0.0:*:*:*:*:*:*:*","matchCriteriaId":"AAAFDC79-44C7-4CD4-BAF7-E4263A94D55E"},{"vulnerable":true,"criteria":"cpe:2.3:a:elastic:kibana:5.0.1:*:*:*:*:*:*:*","matchCriteriaId":"19498633-0929-4FA6-84AA-21D392CF9431"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2016","CveId":"10364","Ordinal":"1","Title":"CVE-2016-10364","CVE":"CVE-2016-10364","Year":"2016"},"notes":[{"CveYear":"2016","CveId":"10364","Ordinal":"1","NoteData":"With X-Pack installed, Kibana versions 5.0.0 and 5.0.1 were not properly authenticating requests to advanced settings and the short URL service, any authenticated user could make requests to those services regardless of their own permissions.","Type":"Description","Title":"CVE-2016-10364"},{"CveYear":"2016","CveId":"10364","Ordinal":"2","NoteData":"2017-06-16","Type":"Other","Title":"Published"},{"CveYear":"2016","CveId":"10364","Ordinal":"3","NoteData":"2017-06-16","Type":"Other","Title":"Modified"}]}}}