CVE-2019-7609

Elastic Kibana

Published 25 Mar 2019 · updated 17 Jun 2026 · Analyzed

10.0 Critical · CVSS 3.1, NVD

Exploited in the wild

CISA added this to its Known Exploited Vulnerabilities catalog on 10 Jan 2022, with a remediation deadline of 10 Jul 2022 for US federal agencies.

Required action: Apply updates per vendor instructions.

Description

Kibana versions before 5.6.15 and 6.6.1 contain an arbitrary code execution flaw in the Timelion visualizer. An attacker with access to the Timelion application could send a request that will attempt to execute javascript code. This could possibly lead to an attacker executing arbitrary commands with permissions of the Kibana process on the host system.

References