4.9
CVSSv3

CVE-2019-7616

Published: 30/07/2019 Updated: 03/03/2023
CVSS v2 Base Score: 4 | Impact Score: 2.9 | Exploitability Score: 8
CVSS v3 Base Score: 4.9 | Impact Score: 3.6 | Exploitability Score: 1.2
VMScore: 356
Vector: AV:N/AC:L/Au:S/C:P/I:N/A:N

Vulnerability Summary

Kibana versions prior to 6.8.2 and 7.2.1 contain a server side request forgery (SSRF) flaw in the graphite integration for Timelion visualizer. An attacker with administrative Kibana access could set the timelion:graphite.url configuration option to an arbitrary URL. This could possibly lead to an attacker accessing external URL resources as the Kibana process on the host system.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

elastic kibana

Github Repositories

POC for CVE-2019-7616 / ESA-2019-09

CVE-2019-7616 POC for CVE-2019-7616 / ESA-2019-09 - Blind SSRF This just a POC not a tool