TROYANOSYVIRUS
Zuruck zu CVEs

CVE-2019-7609

CRITICALCISA KEV
10.0

Beschreibung

Kibana versions before 5.6.15 and 6.6.1 contain an arbitrary code execution flaw in the Timelion visualizer. An attacker with access to the Timelion application could send a request that will attempt to execute javascript code. This could possibly lead to an attacker executing arbitrary commands with permissions of the Kibana process on the host system.

CVE Details

CVSS v3.1 Bewertung10.0
SchweregradCRITICAL
CVSS VektorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
AngriffsvektorNETWORK
KomplexitatLOW
Erforderliche PrivilegienNONE
BenutzerinteraktionNONE
Veroffentlicht3/25/2019
Zuletzt geandert11/7/2025
Quellekev
Honeypot-Sichtungen0

CISA KEV

HerstellerElastic
ProduktKibana
SchwachstellennameKibana Arbitrary Code Execution
KEV Aufnahmedatum2022-01-10
Behebungsfrist2022-07-10
Ransomware-NutzungUnknown

Betroffene Produkte

elastic:kibanaredhat:openshift_container_platform

Schwachen (CWE)

CWE-94CWE-94

IOC Korrelationen

Keine Korrelationen erfasst

This product uses data from the NVD API but is not endorsed or certified by the NVD.