← Zuruck zu CVEs
CVE-2019-7609
CRITICALCISA KEV10.0
Beschreibung
Kibana versions before 5.6.15 and 6.6.1 contain an arbitrary code execution flaw in the Timelion visualizer. An attacker with access to the Timelion application could send a request that will attempt to execute javascript code. This could possibly lead to an attacker executing arbitrary commands with permissions of the Kibana process on the host system.
CVE Details
CVSS v3.1 Bewertung10.0
SchweregradCRITICAL
CVSS VektorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
AngriffsvektorNETWORK
KomplexitatLOW
Erforderliche PrivilegienNONE
BenutzerinteraktionNONE
Veroffentlicht3/25/2019
Zuletzt geandert11/7/2025
Quellekev
Honeypot-Sichtungen0
CISA KEV
HerstellerElastic
ProduktKibana
SchwachstellennameKibana Arbitrary Code Execution
KEV Aufnahmedatum2022-01-10
Behebungsfrist2022-07-10
Ransomware-NutzungUnknown
Betroffene Produkte
elastic:kibanaredhat:openshift_container_platform
Schwachen (CWE)
CWE-94CWE-94
Referenzen
http://packetstormsecurity.com/files/174569/Kibana-Timelion-Prototype-Pollution-Remote-Code-Execution.html(security@elastic.co)
https://access.redhat.com/errata/RHBA-2019:2824(security@elastic.co)
https://access.redhat.com/errata/RHSA-2019:2860(security@elastic.co)
https://discuss.elastic.co/t/elastic-stack-6-6-1-and-5-6-15-security-update/169077(security@elastic.co)
https://www.elastic.co/community/security(security@elastic.co)
http://packetstormsecurity.com/files/174569/Kibana-Timelion-Prototype-Pollution-Remote-Code-Execution.html(af854a3a-2127-422b-91ae-364da2661108)
https://access.redhat.com/errata/RHBA-2019:2824(af854a3a-2127-422b-91ae-364da2661108)
https://access.redhat.com/errata/RHSA-2019:2860(af854a3a-2127-422b-91ae-364da2661108)
https://discuss.elastic.co/t/elastic-stack-6-6-1-and-5-6-15-security-update/169077(af854a3a-2127-422b-91ae-364da2661108)
https://www.elastic.co/community/security(af854a3a-2127-422b-91ae-364da2661108)
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2019-7609(134c704f-9b21-4f2e-91b3-4a467353bcc0)
IOC Korrelationen
Keine Korrelationen erfasst
This product uses data from the NVD API but is not endorsed or certified by the NVD.