CVE-2019-7609
Kibana versions before 5.6.15 and 6.6.1 contain an arbitrary code execution flaw in the Timelion visualizer. An attacker with access to the...
Basic Information
- CVE State
- PUBLISHED
- Reserved Date
- February 07, 2019
- Published Date
- March 25, 2019
- Last Updated
- February 07, 2025
- Vendor
- Elastic
- Product
- Kibana
- Description
- Kibana versions before 5.6.15 and 6.6.1 contain an arbitrary code execution flaw in the Timelion visualizer. An attacker with access to the Timelion application could send a request that will attempt to execute javascript code. This could possibly lead to an attacker executing arbitrary commands with permissions of the Kibana process on the host system.
CVSS Scores
SSVC Information
- Exploitation
- active
- Automatable
- Yes
- Technical Impact
- total
References
Known Exploited Vulnerability Information
Source | Added Date |
---|---|
CISA | 2022-01-10 00:00:00 UTC |
Scanner Integrations
Scanner | URL | Date Detected |
---|---|---|
Metasploit | https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/linux/http/kibana_timelion_prototype_pollution_rce.rb | 2025-04-29 11:01:13 UTC |
Nuclei | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2019/CVE-2019-7609.yaml | 2025-04-26 00:00:00 UTC |
Potential Proof of Concepts
Warning: These PoCs have not been tested and could contain malware. Use at your own risk.
kibana_timelion_prototype_pollution_rce
Type: metasploit • Created: Unknown
Akshay15-png/CVE-2019-7609
Type: github • Created: 2024-06-01 05:10:58 UTC • Stars: 1
wolf1892/CVE-2019-7609
Type: github • Created: 2022-02-10 06:22:54 UTC • Stars: 0
dnr6419/CVE-2019-7609
Type: github • Created: 2021-08-24 04:38:26 UTC • Stars: 1
rhbb/CVE-2019-7609
Type: github • Created: 2020-04-03 10:23:03 UTC • Stars: 1
hekadan/CVE-2019-7609
Type: github • Created: 2019-12-01 14:29:22 UTC • Stars: 21
LandGrey/CVE-2019-7609
Type: github • Created: 2019-10-21 15:31:13 UTC • Stars: 163
mpgn/CVE-2019-7609
Type: github • Created: 2019-10-21 07:32:31 UTC • Stars: 55