Kibana versions before 5.6.15 and 6.6.1 contain an...
Critical severity
Unreviewed
Published
May 13, 2022
to the GitHub Advisory Database
•
Updated Sep 9, 2023
Description
Published by the National Vulnerability Database
Mar 25, 2019
Published to the GitHub Advisory Database
May 13, 2022
Last updated
Sep 9, 2023
Kibana versions before 5.6.15 and 6.6.1 contain an arbitrary code execution flaw in the Timelion visualizer. An attacker with access to the Timelion application could send a request that will attempt to execute javascript code. This could possibly lead to an attacker executing arbitrary commands with permissions of the Kibana process on the host system.
References