CVE-2019-7609
100Vexday Risk Score
Patch now. It under exploitation confirmed by CISA and has a working public exploit.
ssvc Actcvss 9.8epss 95%
from disclosure to weapon207 days
Published on NVDMar 25
1st PoC+207d
metasploit+219d
CISA KEV+1022d
exploitation probability
95%top 1% of all CVEs
observed exploitation
yesCISA + VulnCheck
26 public exploit(s)
Action required by CISAfederal deadline: 2022-07-10
Apply updates per vendor instructions.
Researched and written with AI from the vendor advisory and public analysis, with the sources above. Always confirm the fixed version in the official advisory before acting.
Kibana versions before 5.6.15 and 6.6.1 contain an arbitrary code execution flaw in the Timelion visualizer. An attacker with access to the Timelion application could send a request that will attempt to execute javascript code. This could possibly lead to an attacker executing arbitrary commands with permissions of the Kibana process on the host system.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected products
Elastic · Kibanapublic PoCs found — 26
githubgithub.com/LandGrey/CVE-2019-7609★ 167githubgithub.com/jas502n/kibana-RCE★ 89githubgithub.com/mpgn/CVE-2019-7609★ 56githubgithub.com/hekadan/CVE-2019-7609★ 21githubgithub.com/Cr4ckC4t/cve-2019-7609★ 4githubgithub.com/rhbb/CVE-2019-7609★ 1githubgithub.com/dnr6419/CVE-2019-7609★ 1githubgithub.com/Akshay15-png/CVE-2019-7609★ 1githubgithub.com/wolf1892/CVE-2019-7609★ 0githubgithub.com/aleister1102/kibana-prototype-pollusion★ 0githubgithub.com/toxxxaka/CVE-2019-7609★ 0githubgithub.com/d0x-awrqxavc/CVE-2019-7609-KibanaRCE★ 0vulncheckvulncheck.com/xdb/e88fe8b26b66unverifiedcve_referencepacketstormsecurity.com/files/174569/Kibana-Timelion-Prototype-Pollution-Remote-Code-Execution.htmlunverifiedvulncheckvulncheck.com/xdb/a7f51bb4593funverifiedvulncheckvulncheck.com/xdb/1293a1a85b89unverifiedvulncheckvulncheck.com/xdb/baa23d069da5unverifiedvulncheckvulncheck.com/xdb/72f85a29c165unverifiedvulncheckvulncheck.com/xdb/31a2493d581cunverifiedvulncheckvulncheck.com/xdb/b2f2b26f8c21unverifiedvulncheckvulncheck.com/xdb/b89478e4dff2unverifiedvulncheckvulncheck.com/xdb/99729775468dunverifiedvulncheckvulncheck.com/xdb/c711254ccffcunverifiedvulncheckvulncheck.com/xdb/1c48e403c9e9unverifiedvulncheckvulncheck.com/xdb/47c366ae2f29unverifiedvulncheckvulncheck.com/xdb/6ec76e8d16e1unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
References
http://packetstormsecurity.com/files/174569/Kibana-Timelion-Prototype-Pollution-Remote-Code-Execution.htmlhttps://access.redhat.com/errata/RHBA-2019:2824https://access.redhat.com/errata/RHSA-2019:2860https://discuss.elastic.co/t/elastic-stack-6-6-1-and-5-6-15-security-update/169077https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2019-7609https://www.elastic.co/community/security