VDB
CVE-2019-7609
CVE-2019-7609
PUBLISHED
KEV
CVSS 10 CRITICAL
Kibana versions before 5.6.15 and 6.6.1 contain an arbitrary code execution flaw in the Timelion visualizer. An attacker with access to the Timelion application could send a request that will attempt to execute javascript code. This could possibly lead to an attacker executing arbitrary commands with permissions of the Kibana process on the host system.
EPSS 95.34% · 99.9th percentile
Risk Scores
CVSS 3.1
10
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
EPSS Score
95.34%
99.9th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| elastic | kibana | 6.0.0, 0, 0 |
| Elastic | Kibana | before 5.6.15 and 6.6.1, * |
| redhat | openshift_container_platform | 3.11, 4.1, 4.1 |
Timeline
- CVE Published
- Jan 19, 1970 VulnCheck XDB Entry
- Jan 19, 1970 VulnCheck XDB Entry
- Jan 19, 1970 VulnCheck XDB Entry
- Jan 19, 1970 VulnCheck XDB Entry
- Jan 19, 1970 VulnCheck XDB Entry
- Jan 20, 1970 VulnCheck XDB Entry
- Jan 20, 1970 VulnCheck XDB Entry
- Jan 20, 1970 VulnCheck XDB Entry
- Jan 20, 1970 VulnCheck XDB Entry
- Jan 20, 1970 VulnCheck XDB Entry
- Jan 20, 1970 VulnCheck XDB Entry
References
- Nuclei Template exploit
- RHSA-2019:2860 vendor-advisory
- http://packetstormsecurity.com/files/174569/Kibana-Timelion-Prototype-Pollution-Remote-Code-Execution.html url
- https://www.elastic.co/community/security url
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2019-7609 advisory
- https://access.redhat.com/errata/RHBA-2019:2824 advisory
- https://discuss.elastic.co/t/elastic-stack-6-6-1-and-5-6-15-security-update/169077 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2019-7609 advisory