CRITICAL🚩 CISA KEV⚡ EXPLOIT✓ PATCH🇵🇱 Wersja polska

CVE-2019-7609

CVSS 10.0v3.1pub. 2019-03-25upd. 2025-11-07

Kibana versions before 5.6.15 and 6.6.1 contain an arbitrary code execution flaw in the Timelion visualizer. An attacker with access to the Timelion application could send a request that will attempt to execute javascript code. This could possibly lead to an attacker executing arbitrary commands with permissions of the Kibana process on the host system.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
  • Elastic Kibana

    APP
    Elastic
    < 5.6.156.0.0 – 6.6.1 (excl.)
  • Red Hat OpenShift Container Platform

    APP
    Redhat
    3.114.1

CISA KEV — detailsi

Vendori
Elastic
Producti
Kibana
Added to KEVi
January 10, 2022
Remediation deadline (US Federal)i
July 10, 2022(overdue)
Required action (CISA)i

Apply updates per vendor instructions.

CISA descriptioni

Kibana contain an arbitrary code execution flaw in the Timelion visualizer.

🔴
IMMEDIATE ACTION
Actively exploited in the wild (CISA KEV). Patch immediately.
CISA DEADLINE: 10 lipca 2022
Tags
RCE
CWE
References

Related vulnerabilities

CVE-2019-1003029CRITICAL9.9⚠ KEVPL ✓same product

Jenkins Script Security Plugin — sandbox bypass umożliwiający RCE

CVE-2019-1003030CRITICAL9.9⚠ KEVPL ✓same product

Jenkins Pipeline Groovy Plugin — bypass sandbox i wykonanie kodu (RCE)

CVE-2018-1000861CRITICAL9.8⚠ KEVPL ✓same product

RCE w Jenkins — nieuprawnione wywołanie metod przez Stapler framework

CVE-2026-4408CRITICAL9.0PL ✓same product

Samba: RCE przez command injection w 'check password script' z podstawieniem %u

CVE-2026-4480CRITICAL9.0PL ✓same product

Samba: command injection w podsystemie drukowania przez podstawienie %J