Kibana versions 4.0.0, 4.0.1 and 4.0.2 are vulnerable to a cross-site scripting (XSS) attack. The attack allows execution of arbitrary JavaScript in the context of the userâ??s browser.
Kibana 3 is in the ports tree, kibana 4 is a total rewrite so I don't think we are affected.
Good catch. Kibana 4 isn't in the tree and the advisory is clear on affected versions. There are two open PRs for adding a Kibana 4 port. For bug 200582 in https://bugs.freebsd.org/200582, I've provided this information and mentioned it would have to be addressed. That was the first submission. Bug 200653 was the second submission in https://bugs.freebsd.org/200653. That wasn't portlint clean and didn't have build logs so I provided some feedback to the author, mentioned the security issue, and recommended he close the duplicate PR and contribute to the first.