Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2020-7013

Опубликовано: 03 июн. 2020
Источник: redhat
CVSS3: 7.2

Описание

Kibana versions before 6.8.9 and 7.7.0 contain a prototype pollution flaw in TSVB. An authenticated attacker with privileges to create TSVB visualizations could insert data that would cause Kibana to execute arbitrary code. This could possibly lead to an attacker executing code with the permissions of the Kibana process on the host system.

Отчет

To mitigate this vulnerability you can set "metrics.enabled: false" in kibana.yml

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat OpenShift Container Platform 3.11kibanaWill not fix
Red Hat OpenShift Container Platform 4kibanaWill not fix
Red Hat OpenShift Container Platform 4.6openshift4/ose-logging-kibana6FixedRHSA-2020:429827.10.2020

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-94
https://bugzilla.redhat.com/show_bug.cgi?id=1849044kibana: Prototype pollution in TSVB could result in arbitrary code execution (ESA-2020-06)

7.2 High

CVSS3

Связанные уязвимости

CVSS3: 7.2
nvd
больше 5 лет назад

Kibana versions before 6.8.9 and 7.7.0 contain a prototype pollution flaw in TSVB. An authenticated attacker with privileges to create TSVB visualizations could insert data that would cause Kibana to execute arbitrary code. This could possibly lead to an attacker executing code with the permissions of the Kibana process on the host system.

CVSS3: 7.2
debian
больше 5 лет назад

Kibana versions before 6.8.9 and 7.7.0 contain a prototype pollution f ...

github
больше 3 лет назад

Kibana versions before 6.8.9 and 7.7.0 contain a prototype pollution flaw in TSVB. An authenticated attacker with privileges to create TSVB visualizations could insert data that would cause Kibana to execute arbitrary code. This could possibly lead to an attacker executing code with the permissions of the Kibana process on the host system.

7.2 High

CVSS3