The floragunn Search Guard plugin before 6.x-16 for Kibana allows URL injection for login redirects on the login page when basePath is set.
https://github.com/floragunncom/search-guard-kibana-plugin/pull/140
https://docs.search-guard.com/latest/changelog-kibana-6.x-16