This issue is related to #225363 and #169963. We have known for quite some time that JavaScript template strings break inline script monitors (monitors made by typing/pasting code to the Kibana UI).
CSRF protection on all forms Rate limiting for login attempts Input validation and sanitization Secure password hashing No default credentials ...