Kibana versions before 5.6.15 and 6.6.1 contain an arbitrary code execution flaw in the Timelion visualizer. An attacker with access to the Timelion application could send a request that will attempt to execute javascript code. This could possibly lead to an attacker executing arbitrary commands with permissions of the Kibana process on the host system.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:HElastic Kibana
APPElastic< 5.6.156.0.0 – 6.6.1 (excl.)Red Hat OpenShift Container Platform
APPRedhat3.114.1
CISA KEV — detailsi
- Vendori
- Elastic
- Producti
- Kibana
- Added to KEVi
- January 10, 2022
- Remediation deadline (US Federal)i
- July 10, 2022(overdue)
Apply updates per vendor instructions.
Kibana contain an arbitrary code execution flaw in the Timelion visualizer.
Related vulnerabilities
Jenkins Script Security Plugin — sandbox bypass umożliwiający RCE
Jenkins Pipeline Groovy Plugin — bypass sandbox i wykonanie kodu (RCE)
RCE w Jenkins — nieuprawnione wywołanie metod przez Stapler framework
Samba: RCE przez command injection w 'check password script' z podstawieniem %u
Samba: command injection w podsystemie drukowania przez podstawienie %J