⚠️ CISA Known Exploited Vulnerability
Active ThreatThis vulnerability is listed in CISA's Known Exploited Vulnerabilities (KEV) catalog. Active exploitation has been observed in the wild. This poses significant risk to federal enterprises and should be prioritized for immediate patching.
CVE-2019-7609
Critical CISA KEVVulnerability Description
Kibana versions before 5.6.15 and 6.6.1 contain an arbitrary code execution flaw in the Timelion visualizer. An attacker with access to the Timelion application could send a request that will attempt to execute javascript code. This could possibly lead to an attacker executing arbitrary commands with permissions of the Kibana process on the host system.
CVSS Metrics
Common Vulnerability Scoring System
Vector String:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Known Affected Software
2 configuration(s) from 1 vendor(s)
cpe:2.3:a:redhat:openshift_container_platform:3.11:*:*:*:*:*:x86:*
cpe:2.3:a:redhat:openshift_container_platform:4.1:*:*:*:*:*:*:*
References & Resources
-
http://packetstormsecurity.com/files/174569/Kibana-Timelion-Prototype-Pollution-Remote-Code-Execution.htmlsecurity@elastic.co Exploit Third Party Advisory VDB Entry
-
https://access.redhat.com/errata/RHBA-2019:2824security@elastic.co Third Party Advisory
-
https://access.redhat.com/errata/RHSA-2019:2860security@elastic.co Third Party Advisory
-
https://discuss.elastic.co/t/elastic-stack-6-6-1-and-5-6-15-security-update/169077security@elastic.co Vendor Advisory
-
https://www.elastic.co/community/securitysecurity@elastic.co Broken Link Vendor Advisory
-
http://packetstormsecurity.com/files/174569/Kibana-Timelion-Prototype-Pollution-Remote-Code-Execution.htmlaf854a3a-2127-422b-91ae-364da2661108 Exploit Third Party Advisory VDB Entry
-
https://access.redhat.com/errata/RHBA-2019:2824af854a3a-2127-422b-91ae-364da2661108 Third Party Advisory
-
https://access.redhat.com/errata/RHSA-2019:2860af854a3a-2127-422b-91ae-364da2661108 Third Party Advisory
-
https://discuss.elastic.co/t/elastic-stack-6-6-1-and-5-6-15-security-update/169077af854a3a-2127-422b-91ae-364da2661108 Vendor Advisory
-
https://www.elastic.co/community/securityaf854a3a-2127-422b-91ae-364da2661108 Broken Link Vendor Advisory
-
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2019-7609134c704f-9b21-4f2e-91b3-4a467353bcc0 US Government Resource
Severity Details
CISA KEV Status
Listed in CISA's Known Exploited Vulnerabilities catalog
Key Information
- Published Date
- March 25, 2019
