CVE-2019-7609
Kibana Arbitrary Code Execution
Does this matter?
Known to be exploited in the wild (CISA KEV, CISA remediation deadline 10 July 2022). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.
Description
Kibana versions before 5.6.15 and 6.6.1 contain an arbitrary code execution flaw in the Timelion visualizer. An attacker with access to the Timelion application could send a request that will attempt to execute javascript code. This could possibly lead to an attacker executing arbitrary commands with permissions of the Kibana process on the host system.
- CVSS 3.1
- 10.0 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
- EPSS
- 95.34% probability · 100th percentile
- CISA KEV
- Listed 10 January 2022 · due 10 July 2022
- Weakness
- CWE-94
- Affected
- elastic/kibana · redhat/openshift container platform
- Source
- security@elastic.co
CISA notes
Apply updates per vendor instructions. https://nvd.nist.gov/vuln/detail/CVE-2019-7609
References
- http://packetstormsecurity.com/files/174569/Kibana-Timelion-Prototype-Pollution-Remote-Code-Execution.htmlExploit, Third Party Advisory, VDB Entry
- https://access.redhat.com/errata/RHBA-2019:2824Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:2860Third Party Advisory
- https://discuss.elastic.co/t/elastic-stack-6-6-1-and-5-6-15-security-update/169077Vendor Advisory
- https://www.elastic.co/community/securityBroken Link, Vendor Advisory
- http://packetstormsecurity.com/files/174569/Kibana-Timelion-Prototype-Pollution-Remote-Code-Execution.htmlExploit, Third Party Advisory, VDB Entry
- https://access.redhat.com/errata/RHBA-2019:2824Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:2860Third Party Advisory
- https://discuss.elastic.co/t/elastic-stack-6-6-1-and-5-6-15-security-update/169077Vendor Advisory
- https://www.elastic.co/community/securityBroken Link, Vendor Advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2019-7609US Government Resource
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.