← Back to CVE List
Vulnerability Intelligence Report

CVE-2018-17246

Kibana versions before 6.4.3 and 5.6.13 contain an arbitrary file inclusion flaw in the Console plugin. An attacker with access to the Kibana Console API could send a request that will attempt to execute javascript code. This could possibly lead to an attacker executing arbitrary commands with permissions of the Kibana process on the host system.

Nuclei Template
CVSS Base Score
9.8
CRITICAL
EPSS Probability:82.25%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—

Weaknesses (CWE)

CWE-73 ↗CWE-73: External Control of File Name or Path

Affected Products & Versions

Vendor Product Affected Versions
Elastic Kibana before 6.4.3 and 5.6.13 (affected)

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

Nuclei Template
SCANNER AVAILABLE
EPSS Score
82.251%

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityElastic · Vendor · Netherlands
Reserved2018-09-20T00:00:00
Published2018-12-20T22:00:00
Patch Date2018-12-20
Last Updated2024-08-05T10:47:04

LINK COPIED TO CLIPBOARD