CVE-2019-7609

Kibana versions before 5.6.15 and 6.6.1 contain an arbitrary code execution flaw in the Timelion visualizer. An attacker with access to the...

Basic Information

CVE State
PUBLISHED
Reserved Date
February 07, 2019
Published Date
March 25, 2019
Last Updated
February 07, 2025
Vendor
Elastic
Product
Kibana
Description
Kibana versions before 5.6.15 and 6.6.1 contain an arbitrary code execution flaw in the Timelion visualizer. An attacker with access to the Timelion application could send a request that will attempt to execute javascript code. This could possibly lead to an attacker executing arbitrary commands with permissions of the Kibana process on the host system.

CVSS Scores

SSVC Information

Exploitation
active
Automatable
Yes
Technical Impact
total

Exploit Status

Exploited in the Wild
Yes (added 2022-01-10 00:00:00 UTC) Source
Proof of Concept Available
Yes (added 2024-06-01 05:10:58 UTC) Source

Known Exploited Vulnerability Information

Source Added Date
CISA 2022-01-10 00:00:00 UTC

Potential Proof of Concepts

Warning: These PoCs have not been tested and could contain malware. Use at your own risk.

kibana_timelion_prototype_pollution_rce

Type: metasploit • Created: Unknown

Metasploit module for CVE-2019-7609

Akshay15-png/CVE-2019-7609

Type: github • Created: 2024-06-01 05:10:58 UTC • Stars: 1

Exploit for CVE-2019-7609 in python

wolf1892/CVE-2019-7609

Type: github • Created: 2022-02-10 06:22:54 UTC • Stars: 0

docker lab setup for kibana-7609

dnr6419/CVE-2019-7609

Type: github • Created: 2021-08-24 04:38:26 UTC • Stars: 1

Kibana Prototype Pollution

rhbb/CVE-2019-7609

Type: github • Created: 2020-04-03 10:23:03 UTC • Stars: 1

hekadan/CVE-2019-7609

Type: github • Created: 2019-12-01 14:29:22 UTC • Stars: 21

LandGrey/CVE-2019-7609

Type: github • Created: 2019-10-21 15:31:13 UTC • Stars: 163

exploit CVE-2019-7609(kibana RCE) on right way by python2 scripts

mpgn/CVE-2019-7609

Type: github • Created: 2019-10-21 07:32:31 UTC • Stars: 55

RCE on Kibana versions before 5.6.15 and 6.6.0 in the Timelion visualizer