Junglewise Threat Intelligence

CVE-2019-7609: Kibana Arbitrary Code Execution

CVE-2019-7609 · Severity: critical · CVSS 10 · Exploited in the wild · Published 2022-01-10

Technologies: Elastic Kibana. Vendors: Red Hat, Elastic.

Executive brief

Kibana contains an arbitrary code execution vulnerability in the Timelion visualizer. An attacker can send a crafted request to execute JavaScript code, potentially leading to arbitrary command execution with the permissions of the Kibana process.

Affected products

  • Elastic Kibana before 5.6.15, and 6.0.0 to 6.6.1
  • Red Hat Openshift Container Platform 3.11, 4.1

Timeline

  • 2019-02-19: advisory: Elastic security update for 6.6.1 and 5.6.15 published
  • 2019-03-26: disclosed: Initial NVD analysis published
  • 2022-01-10: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2022-01-10: exploited: Reported as exploited in the wild

Related threats