VDB
GSD-2019-7609
GSD-2019-7609
PUBLISHED
CVSS 9.800000190734863 CRITICAL
Kibana versions before 5.6.15 and 6.6.1 contain an arbitrary code execution flaw in the Timelion visualizer. An attacker with access to the Timelion application could send a request that will attempt to execute javascript code. This could possibly lead to an attacker executing arbitrary commands with permissions of the Kibana process on the host system.
Risk Scores
CVSS 3.1
9.800000190734863
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Elastic | Kibana | before 5.6.15 and 6.6.1 |
Timeline
- Mar 25, 2019 CVE Published
- Jun 14, 2023 PoC Published
- Sep 8, 2023 PoC Published
- Dec 24, 2024 PoC Published
- Feb 6, 2025 PoC Published
- Feb 23, 2025 PoC Published
- Feb 23, 2025 PoC Published
- Aug 31, 2025 PoC Published
- Sep 22, 2025 PoC Published
- Oct 23, 2025 PoC Published
- Feb 2, 2026 PoC Published
- Apr 15, 2026 Distribution Patch
References
- https://discuss.elastic.co/t/elastic-stack-6-6-1-and-5-6-15-security-update/169077 url
- https://www.elastic.co/community/security url
- RHSA-2019:2860 advisory
- RHBA-2019:2824 advisory
- http://packetstormsecurity.com/files/174569/Kibana-Timelion-Prototype-Pollution-Remote-Code-Execution.html exploit
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2019-7609 advisory