A flaw allowing arbitrary code execution was discovered in Kibana. An attacker with access to ML and Alerting connector features, as well as write access to internal ML indices can trigger a prototype pollution vulnerability, ultimately leading to arbitrary code execution.
The vulnerability consists of the possibility of triggering prototype pollution (CWE-1321) by an attacker with access to ML (Machine Learning) functionality and Alerting connector, as well as write permissions to internal ML indices. Through manipulation of JavaScript object prototypes, it is possible to inject and execute arbitrary code (CWE-94) on the server side. The attack does not require user interaction, but it does require elevated privileges in the application.
An attacker can execute arbitrary code on the Kibana server, leading to complete compromise of the instance — including gaining access to sensitive data, modifying configuration, and potential lateral movement in the infrastructure.
Kibana should be updated to version 8.14.2 or 7.17.23 according to the vendor information published at: https://discuss.elastic.co/t/kibana-8-14-2-7-17-23-security-update-esa-2024-22/. Additionally, as a temporary measure, it is advisable to restrict access to ML functionality and Alerting connector exclusively to trusted users.
Elastic Kibana — versions indicated in vendor references (patch delivered in versions 8.14.2 and 7.17.23)
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:HElastic Kibana
APPElastic7.7.0 – 7.17.23 (excl.)8.0.0 – 8.14.2 (excl.)
Related vulnerabilities
RCE w Kibana Timelion — wykonanie kodu z uprawnieniami procesu
Prototype Pollution w Kibana prowadzące do RCE przez HTTP
Prototype Pollution w Elastic Kibana umożliwia zdalne wykonanie kodu (RCE)
RCE przez deserializację YAML w Elastic Kibana
Deserializacja YAML w Kibana umożliwia zdalne wykonanie kodu (RCE)