CVE-2020-7013Code Injection in Kibana

CWE-94Code Injection5 documents5 sources
Severity
7.2HIGHNVD
EPSS
1.4%
top 19.73%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 3
Latest updateMay 24

Description

Kibana versions before 6.8.9 and 7.7.0 contain a prototype pollution flaw in TSVB. An authenticated attacker with privileges to create TSVB visualizations could insert data that would cause Kibana to execute arbitrary code. This could possibly lead to an attacker executing code with the permissions of the Kibana process on the host system.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:HExploitability: 1.2 | Impact: 5.9

Affected Packages2 packages

NVDelastic/kibana7.0.07.7.0+1
CVEListV5elastic/kibanabefore 6.8.9 and 7.7.0

Also affects: Openshift Container Platform 3.11, 4.0

🔴Vulnerability Details

2
GHSA
GHSA-7j4x-vm2f-rhf2: Kibana versions before 62022-05-24
CVEList
CVE-2020-7013: Kibana versions before 62020-06-03

📋Vendor Advisories

1
Red Hat
kibana: Prototype pollution in TSVB could result in arbitrary code execution (ESA-2020-06)2020-06-03

💬Community

1
Bugzilla
CVE-2020-7013 kibana: Prototype pollution in TSVB could result in arbitrary code execution (ESA-2020-06)2020-06-19
CVE-2020-7013 — Code Injection in Elastic Kibana | cvebase