CVE-2019-7609criticalunder attackCWE-94

CVE-2019-7609: critical vulnerability in Elastic Kibana

Published · Updated

100Vexday Risk Score

Patch now. It under exploitation confirmed by CISA and has a working public exploit.

ssvc Actcvss 9.8epss 95%
from disclosure to weapon207 days
Published on NVDMar 25
1st PoC+207d
metasploit+219d
CISA KEV+1022d
exploitation probability
95%top 1% of all CVEs
observed exploitation
yesCISA + VulnCheck
26 public exploit(s)
What the vendors declare (VEX)

Official vendor statements in CSAF/VEX format: whether their product is affected, already fixed, or ruled out — and why. These are the vendor's assertions, not Vexday's judgment.

Fixed
2 products (156 components)
Red Hat OpenShift Container Platform 3.11 · Red Hat OpenShift Container Platform 4.1
Not affected
8 products (12 components) — because the vulnerable code is not present in the product
Red Hat OpenShift Container Platform 3.10 · Red Hat OpenShift Container Platform 3.6 · Red Hat OpenShift Container Platform 3.7 · Red Hat OpenShift Container Platform 3.9 · Red Hat OpenShift Container Platform 3.4 · and others 3
Action required by CISAfederal deadline: 2022-07-10

Apply updates per vendor instructions.

In short

Kibana's Timelion visualizer allows attackers with application access to execute arbitrary JavaScript code, which can lead to running commands on the server with Kibana's permissions.

Technical detail

CVE-2019-7609 is an arbitrary code execution vulnerability in Timelion visualizer (CWE-94: Improper Control of Generation of Code) affecting Kibana versions before 5.6.15 and 6.6.1. An authenticated attacker can craft a malicious request to inject and execute JavaScript, potentially achieving remote code execution with the privileges of the Kibana process on the host system.

Summary generated and translated by AI from the official description.

The full analysis of this CVE is available in Portuguese →

Kibana versions before 5.6.15 and 6.6.1 contain an arbitrary code execution flaw in the Timelion visualizer. An attacker with access to the Timelion application could send a request that will attempt to execute javascript code. This could possibly lead to an attacker executing arbitrary commands with permissions of the Kibana process on the host system.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected products
Elastic · Kibana
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.