CVE-2019-7609: critical vulnerability in Elastic Kibana
Published · Updated
Patch now. It under exploitation confirmed by CISA and has a working public exploit.
Official vendor statements in CSAF/VEX format: whether their product is affected, already fixed, or ruled out — and why. These are the vendor's assertions, not Vexday's judgment.
Apply updates per vendor instructions.
Kibana's Timelion visualizer allows attackers with application access to execute arbitrary JavaScript code, which can lead to running commands on the server with Kibana's permissions.
CVE-2019-7609 is an arbitrary code execution vulnerability in Timelion visualizer (CWE-94: Improper Control of Generation of Code) affecting Kibana versions before 5.6.15 and 6.6.1. An authenticated attacker can craft a malicious request to inject and execute JavaScript, potentially achieving remote code execution with the privileges of the Kibana process on the host system.
The full analysis of this CVE is available in Portuguese →
In the same product, most dangerous first.