CVE-2019-7609

Scores

EPSS

0.944High94.4%
0%20%40%60%80%100%

Percentile: 94.4%

CVSS

7.5High3.x
0246810

CVSS Score: 7.5/10

All CVSS Scores

CVSS 3.x
7.5

Vector: CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

CVSS 2.0
10.0

Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Description

Kibana versions before 5.6.15 and 6.6.1 contain an arbitrary code execution flaw in the Timelion visualizer. An attacker with access to the Timelion application could send a request that will attempt to execute javascript code. This could possibly lead to an attacker executing arbitrary commands with permissions of the Kibana process on the host system.

Scaner-VS 7 — a modern vulnerability management solution

Uses this database for vulnerability detection. High-speed search, cross-platform, advanced configuration audit, and flexible filtering. Suitable for organizations of any size.
Learn more about Scaner-VS 7

Sources

nvdredhat

CWEs

CWE-20CWE-94

Related Vulnerabilities

Exploits

Exploit ID: CVE-2019-7609

Source: github-poc

URL: https://github.com/Akshay15-png/CVE-2019-7609

Recommendations

Source: nvd

For OpenShift Container Platform 4.1 see the following documentation, whichwill be updated shortly for release 4.1.18, for important instructions onhow to upgrade your cluster and fully apply this asynchronous errataupdate:
https://docs.openshift.com/container-platform/4.1/release_notes/ocp-4-1-release-notes.html

URL: https://access.redhat.com/errata/RHSA-2019:2860

Vulnerable Software (3)

Type: Configuration

Product: kibana

Operating System: rhel

Trait:
{
  "fixed": "5.6.16-2.el7"
}

Source: redhat

Type: Configuration

Vendor: elastic

Product: kibana

Operating System: * * *

Trait:
{
  "cpe_match": [
    {
      "cpe23uri": "cpe:2.3:a:elastic:kibana:*:*:*:*:*:*:*:*",
      "versionEndExcluding": "5.6.15",
      "vulnerable": true
    },
    {
      "cpe23uri": "cpe:2.3:a:elastic...

Source: nvd

Type: Configuration

Vendor: redhat

Product: openshift_container_platform

Operating System: * * *

Trait:
{
  "cpe_match": [
    {
      "cpe23uri": "cpe:2.3:a:redhat:openshift_container_platform:3.11:*:*:*:*:*:*:*",
      "vulnerable": true
    },
    {
      "cpe23uri": "cpe:2.3:a:redhat:openshift_conta...

Source: nvd