PT-2024-5372 · Elastic · Kibana

CVE-2024-37287

·

Published

2024-08-06

·

Updated

2024-09-10

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Kibana versions prior to 8.14.2 Kibana versions prior to 7.17.23
Description A flaw allowing arbitrary code execution was discovered in Kibana. An attacker with access to ML and Alerting connector features, as well as write access to internal ML indices can trigger a prototype pollution vulnerability, ultimately leading to arbitrary code execution. At the time of writing, Censys observes 5,183 exposed devices online.
Recommendations For versions prior to 8.14.2, upgrade to version 8.14.2. For versions prior to 7.17.23, upgrade to version 7.17.23.

Exploit

Fix

DoS

Code Injection

Prototype Pollution

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2024-06005
CVE-2024-37287

Affected Products

Kibana