Vulnerability detail
Enriched intelligence for a single CVE
Critical
CVE-2019-7609
PUBLISHEDKibana versions before 5.6.15 and 6.6.1 contain an arbitrary code execution flaw in the Timelion visualizer. An attacker with access to the...
- Vendor
- Elastic
- Product
- Kibana
- Published
- Mar 25, 2019
- EPSS
- —
Description
Kibana versions before 5.6.15 and 6.6.1 contain an arbitrary code execution flaw in the Timelion visualizer. An attacker with access to the Timelion application could send a request that will attempt to execute javascript code. This could possibly lead to an attacker executing arbitrary commands with permissions of the Kibana process on the host system.
CVSS scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
AV:N/AC:L/Au:N/C:C/I:C/A:C
Exploitation status
Exploited in the wild
Recorded 2022-01-10 00:00:00 UTC · Source
SSVC decision points
- Exploitation
- active
- Automatable
- Yes
- Technical impact
- total
References
- https://discuss.elastic.co/t/elastic-stack-6-6-1-and-5-6-15-security-update/169077
- https://www.elastic.co/community/security
- https://access.redhat.com/errata/RHSA-2019:2860
- https://access.redhat.com/errata/RHBA-2019:2824
- http://packetstormsecurity.com/files/174569/Kibana-Timelion-Prototype-Pollution-Remote-Code-Execution.html
Known exploited vulnerability sources
Catalogues that list this CVE as a known exploited vulnerability.
| Source | Added |
|---|---|
| CISA | Jan 10, 2022 |
| CISA | Jan 10, 2022 |
Scanner integrations
| Scanner | Reference | Detected |
|---|---|---|
| Metasploit | https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/linux/http/kibana_timelion_prototype_pollution_rce.rb | Apr 28, 2025 |
| Nuclei | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2019/CVE-2019-7609.yaml | Apr 25, 2025 |
Potential proof of concepts
These PoCs are unverified and could contain malware. Use at your own risk.
metasploit · Created Unknown
Metasploit module for CVE-2019-7609
github · Created 2024-06-01 05:10:58 UTC · 1 stars
Exploit for CVE-2019-7609 in python
github · Created 2022-02-10 06:22:54 UTC · 0 stars
docker lab setup for kibana-7609
github · Created 2020-04-03 10:23:03 UTC · 1 stars
github · Created 2019-12-01 14:29:22 UTC · 21 stars
github · Created 2019-10-21 15:31:13 UTC · 163 stars
exploit CVE-2019-7609(kibana RCE) on right way by python2 scripts
github · Created 2019-10-21 07:32:31 UTC · 55 stars
RCE on Kibana versions before 5.6.15 and 6.6.0 in the Timelion visualizer
Timeline
-
CVE ID Reserved
-
CVE Published to Public
-
Added to KEVIntel
-
Added to KEVIntel
-
Detected by Nuclei
-
Detected by Metasploit