SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityAnalyzed

CVE-2019-7609

Kibana Arbitrary Code Execution

KEVCRITICAL 10.0EPSS 95.3%

Does this matter?

Known to be exploited in the wild (CISA KEV, CISA remediation deadline 10 July 2022). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.

Description

Kibana versions before 5.6.15 and 6.6.1 contain an arbitrary code execution flaw in the Timelion visualizer. An attacker with access to the Timelion application could send a request that will attempt to execute javascript code. This could possibly lead to an attacker executing arbitrary commands with permissions of the Kibana process on the host system.

CVSS 3.1
10.0 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
EPSS
95.34% probability · 100th percentile
CISA KEV
Listed 10 January 2022 · due 10 July 2022
Weakness
CWE-94
Affected
elastic/kibana · redhat/openshift container platform
Source
security@elastic.co

CISA notes

Apply updates per vendor instructions. https://nvd.nist.gov/vuln/detail/CVE-2019-7609

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.