9
CVSSv3

CVE-2019-7610

Published: 25/03/2019 Updated: 30/07/2019
CVSS v2 Base Score: 9.3 | Impact Score: 10 | Exploitability Score: 8.6
CVSS v3 Base Score: 9 | Impact Score: 6 | Exploitability Score: 2.2
VMScore: 829
Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Summary

Kibana versions prior to 6.6.1 contain an arbitrary code execution flaw in the security audit logger. If a Kibana instance has the setting xpack.security.audit.enabled set to true, an attacker could send a request that will attempt to execute javascript code. This could possibly lead to an attacker executing arbitrary commands with permissions of the Kibana process on the host system.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

elastic kibana

Vendor Advisories

Synopsis Important: OpenShift Container Platform 4118 security update Type/Severity Security Advisory: Important Topic An update for kibana is now available for Red Hat OpenShift Container Platform 41Red Hat Product Security has rated this update as having a security impact of Important A Common Vulner ...
Kibana versions before 5615 and 661 contain an arbitrary code execution flaw in the security audit logger If a Kibana instance has the setting xpacksecurityauditenabled set to true, an attacker could send a request that will attempt to execute javascript code This could possibly lead to an attacker executing arbitrary commands with permiss ...