CVE-2019-7609

NVD Published Date: March 25, 2019 at 07:29 PM
NVD Last Modified: July 24, 2024 at 04:58 PM
Download Patch
Vulnerability ID
CVE-2019-7609
Severity
CRITICAL
Severity Score
10.0
Summary
Kibana versions before 5.6.15 and 6.6.1 contain an arbitrary code execution flaw in the Timelion visualizer. An attacker with access to the Timelion application could send a request that will attempt to execute javascript code. This could possibly lead to an attacker executing arbitrary commands with permissions of the Kibana process on the host system.
Mitigation and Patches
-
Metasploit Payload
-
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
CWE ID
CWE-94

Recent Publish

KB5041592

KB5002619

CVE-2019-11510

CVE-2019-11708

KB5002642

KB5002648

See More ...

See SecOps Solution
in action

Schedule Demo