ZeroHour

CVE-2018-17246

CVSS 3.0
9.8 critical
EPSS
82%p100
Published
()
Modified
Description

Kibana versions before 6.4.3 and 5.6.13 contain an arbitrary file inclusion flaw in the Console plugin. An attacker with access to the Kibana Console API could send a request that will attempt to execute javascript code. This could possibly lead to an attacker executing arbitrary commands with permissions of the Kibana process on the host system.

Vendors
elasticredhat
Products
kibana, openshift container platform
Weakness
CWE-73, CWE-829
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.