CVE-2019-7610
Kibana versions before 6.6.1 contain an arbitrary code execution flaw in the security audit logger.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (3.91%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Kibana versions before 6.6.1 contain an arbitrary code execution flaw in the security audit logger. If a Kibana instance has the setting xpack.security.audit.enabled set to true, an attacker could send a request that will attempt to execute javascript code. This could possibly lead to an attacker executing arbitrary commands with permissions of the Kibana process on the host system.
- CVSS 3.0
- 9.0 CRITICALCVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
- EPSS
- 3.91% probability · 90th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-94, CWE-77
- Affected
- elastic/kibana
- Source
- security@elastic.co
References
- https://access.redhat.com/errata/RHBA-2019:2824
- https://access.redhat.com/errata/RHSA-2019:2860
- https://discuss.elastic.co/t/elastic-stack-6-6-1-and-5-6-15-security-update/169077Vendor Advisory
- https://www.elastic.co/community/securityVendor Advisory
- https://access.redhat.com/errata/RHBA-2019:2824
- https://access.redhat.com/errata/RHSA-2019:2860
- https://discuss.elastic.co/t/elastic-stack-6-6-1-and-5-6-15-security-update/169077Vendor Advisory
- https://www.elastic.co/community/securityVendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.