CVE-2019-7609
קריטית 10.0 מנוצלת בשטח (KEV)
ניצול פעיל מאומת — קטלוג CISA KEV
- שם
- Kibana Arbitrary Code Execution
- נוסף לקטלוג
- יעד טיפול (פדרלי)
- פעולה נדרשת
- Apply updates per vendor instructions.
תיאור (מקור, אנגלית)
Kibana versions before 5.6.15 and 6.6.1 contain an arbitrary code execution flaw in the Timelion visualizer. An attacker with access to the Timelion application could send a request that will attempt to execute javascript code. This could possibly lead to an attacker executing arbitrary commands with permissions of the Kibana process on the host system.
מדדים
- CVSS 3.1
-
10.0 (CRITICAL)
מקור הציון: NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H - EPSS — סבירות ניצול
- 95% (אחוזון 100) נכון ל-30/7/2026
- CWE
- CWE-94
מוצרים מושפעים
elastic: kibana; redhat: openshift container platform
קישורים
- https://discuss.elastic.co/t/elastic-stack-6-6-1-and-5-6-15-security-update/16… Vendor Advisory
- https://www.elastic.co/community/security Broken LinkVendor Advisory
- https://discuss.elastic.co/t/elastic-stack-6-6-1-and-5-6-15-security-update/16… Vendor Advisory
- https://www.elastic.co/community/security Broken LinkVendor Advisory
- http://packetstormsecurity.com/files/174569/Kibana-Timelion-Prototype-Pollutio… ExploitThird Party AdvisoryVDB Entry
- http://packetstormsecurity.com/files/174569/Kibana-Timelion-Prototype-Pollutio… ExploitThird Party AdvisoryVDB Entry
- https://access.redhat.com/errata/RHBA-2019:2824 Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:2860 Third Party Advisory
- https://access.redhat.com/errata/RHBA-2019:2824 Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:2860 Third Party Advisory