← Back

CVE-2019-7610

nvd nist
Published: Mar 25, 2019Modified: Nov 21, 2024

JSON object

Loading...
9.0
Vector
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
Exploitability: 2.2 / Impact: 6.0
Source: NVD

Description

Kibana versions before 6.6.1 contain an arbitrary code execution flaw in the security audit logger. If a Kibana instance has the setting xpack.security.audit.enabled set to true, an attacker could send a request that will attempt to execute javascript code. This could possibly lead to an attacker executing arbitrary commands with permissions of the Kibana process on the host system.

Affected (2)

Products: Elastic: Kibana
1 product
Kibana
Configuration A
2 vulnerable
Vulnerable SoftwareAffected Versions
Elastic
Before 5.6.15
From 6.0.0 to 6.6.1

References (8)

Source: security@elastic.co
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory

Timeline

No history available yet.