CVE-2019-7609
Elastic Kibana
Published 25 Mar 2019 · updated 17 Jun 2026 · Analyzed
10.0 Critical · CVSS 3.1, NVD
Exploited in the wild
CISA added this to its Known Exploited Vulnerabilities catalog on 10 Jan 2022, with a remediation deadline of 10 Jul 2022 for US federal agencies.
Required action: Apply updates per vendor instructions.
Description
Kibana versions before 5.6.15 and 6.6.1 contain an arbitrary code execution flaw in the Timelion visualizer. An attacker with access to the Timelion application could send a request that will attempt to execute javascript code. This could possibly lead to an attacker executing arbitrary commands with permissions of the Kibana process on the host system.
References
- packetstormsecurity.com/files/174569/Kibana-Timelion-Prototype-Pollution-Remote-Code-Execution.html · Exploit, Third Party Advisory, VDB Entry
- access.redhat.com/errata/RHBA-2019:2824 · Third Party Advisory
- access.redhat.com/errata/RHSA-2019:2860 · Third Party Advisory
- discuss.elastic.co/t/elastic-stack-6-6-1-and-5-6-15-security-update/169077 · Vendor Advisory
- www.elastic.co/community/security · Broken Link, Vendor Advisory
- www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2019-7609 · US Government Resource