PT-2019-18668 · Elastic · Kibana

Published

2019-07-30

·

Updated

2023-03-03

·

CVE-2019-7616

CVSS v3.1

4.9

Medium

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Kibana versions prior to 6.8.2 Kibana versions prior to 7.2.1
Description The issue is related to a server side request forgery (SSRF) flaw in the graphite integration for the Timelion visualizer. An attacker with administrative access could set the timelion:graphite.url configuration option to an arbitrary URL, potentially allowing access to external URL resources as the Kibana process on the host system.
Recommendations For versions prior to 6.8.2, update to version 6.8.2 or later. For versions prior to 7.2.1, update to version 7.2.1 or later.

Exploit

Fix

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-7616

Affected Products

Kibana