CRITICAL✓ PATCH🇵🇱 Wersja polska

CVE-2024-37287

CVSS 9.1v3.1pub. 2024-08-13upd. 2024-08-22

A flaw allowing arbitrary code execution was discovered in Kibana. An attacker with access to ML and Alerting connector features, as well as write access to internal ML indices can trigger a prototype pollution vulnerability, ultimately leading to arbitrary code execution.

🤖 AI Analysis
How it works

The vulnerability consists of the possibility of triggering prototype pollution (CWE-1321) by an attacker with access to ML (Machine Learning) functionality and Alerting connector, as well as write permissions to internal ML indices. Through manipulation of JavaScript object prototypes, it is possible to inject and execute arbitrary code (CWE-94) on the server side. The attack does not require user interaction, but it does require elevated privileges in the application.

Impact

An attacker can execute arbitrary code on the Kibana server, leading to complete compromise of the instance — including gaining access to sensitive data, modifying configuration, and potential lateral movement in the infrastructure.

Mitigation & patch

Kibana should be updated to version 8.14.2 or 7.17.23 according to the vendor information published at: https://discuss.elastic.co/t/kibana-8-14-2-7-17-23-security-update-esa-2024-22/. Additionally, as a temporary measure, it is advisable to restrict access to ML functionality and Alerting connector exclusively to trusted users.

Who is affected

Elastic Kibana — versions indicated in vendor references (patch delivered in versions 8.14.2 and 7.17.23)

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
  • Elastic Kibana

    APP
    Elastic
    7.7.0 – 7.17.23 (excl.)8.0.0 – 8.14.2 (excl.)
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
Tags
RCE
CWE
References

Related vulnerabilities

CVE-2019-7609CRITICAL10.0⚠ KEVPL ✓same product

RCE w Kibana Timelion — wykonanie kodu z uprawnieniami procesu

CVE-2025-25014CRITICAL9.1PL ✓same product

Prototype Pollution w Kibana prowadzące do RCE przez HTTP

CVE-2025-25015CRITICAL9.9PL ✓same product

Prototype Pollution w Elastic Kibana umożliwia zdalne wykonanie kodu (RCE)

CVE-2024-37285CRITICAL9.1PL ✓same product

RCE przez deserializację YAML w Elastic Kibana

CVE-2024-37288CRITICAL9.9PL ✓same product

Deserializacja YAML w Kibana umożliwia zdalne wykonanie kodu (RCE)