CVE-2020-7013
published 2020-06-03CVE-2020-7013: Kibana versions before 6.8.9 and 7.7.0 contain a prototype pollution flaw in TSVB. An authenticated attacker with privileges to create TSVB visualizations…
PriorityP343high7.2CVSS 3.1
AVNACLPRHUINSUCHIHAH
EPSS
2.15%
80.2th percentile
Kibana versions before 6.8.9 and 7.7.0 contain a prototype pollution flaw in TSVB. An authenticated attacker with privileges to create TSVB visualizations could insert data that would cause Kibana to execute arbitrary code. This could possibly lead to an attacker executing code with the permissions of the Kibana process on the host system.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| elastic | kibana | < 6.8.9 | 6.8.9 |
| elastic | kibana | — | — |
| elastic | kibana | >= 7.0.0 < 7.7.0 | 7.7.0 |
| redhat | openshift_container_platform | — | — |
| redhat | openshift_container_platform | — | — |
CVSS provenance
nvdv3.17.2HIGHCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
nvdv2.06.5MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
vendor_redhat7.2HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-7j4x-vm2f-rhf2: Kibana versions before 6
ghsa_unreviewed·2022-05-24
CVE-2020-7013 [MEDIUM] GHSA-7j4x-vm2f-rhf2: Kibana versions before 6
Kibana versions before 6.8.9 and 7.7.0 contain a prototype pollution flaw in TSVB. An authenticated attacker with privileges to create TSVB visualizations could insert data that would cause Kibana to execute arbitrary code. This could possibly lead to an attacker executing code with the permissions of the Kibana process on the host system.
Red Hat
kibana: Prototype pollution in TSVB could result in arbitrary code execution (ESA-2020-06)
vendor_redhat·2020-06-03·CVSS 7.2
CVE-2020-7013 [HIGH] CWE-94 kibana: Prototype pollution in TSVB could result in arbitrary code execution (ESA-2020-06)
kibana: Prototype pollution in TSVB could result in arbitrary code execution (ESA-2020-06)
Kibana versions before 6.8.9 and 7.7.0 contain a prototype pollution flaw in TSVB. An authenticated attacker with privileges to create TSVB visualizations could insert data that would cause Kibana to execute arbitrary code. This could possibly lead to an attacker executing code with the permissions of the Kibana process on the host system.
Statement: To mitigate this vulnerability you can set "metrics.enabled: false" in kibana.yml
Package: kibana (Red Hat OpenShift Container Platform 3.11) - Will not fix
Package: kibana (Red Hat OpenShift Container Platform 4) - Will not fix
No detection rules found.
No public exploits indexed.
2020-06-03
Published