Vulnerability Intelligence Report
CVE-2018-17246
Kibana versions before 6.4.3 and 5.6.13 contain an arbitrary file inclusion flaw in the Console plugin. An attacker with access to the Kibana Console API could send a request that will attempt to execute javascript code. This could possibly lead to an attacker executing arbitrary commands with permissions of the Kibana process on the host system.
Nuclei Template
CVSS Base Score
9.8
CRITICAL
EPSS Probability:82.25%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—
Weaknesses (CWE)
CWE-73 ↗CWE-73: External Control of File Name or Path
Affected Products & Versions
| Vendor | Product | Affected Versions |
|---|---|---|
| Elastic | Kibana | before 6.4.3 and 5.6.13 (affected) |
References & Technical Advisories
No reference links found.
Threat Intelligence Signals
Identity & Timeline
| Status | PUBLISHED |
| Assigning Authority | Elastic · Vendor · Netherlands |
| Reserved | 2018-09-20T00:00:00 |
| Published | 2018-12-20T22:00:00 |
| Patch Date | 2018-12-20 |
| Last Updated | 2024-08-05T10:47:04 |
Community Chatter & Buzz