ZeroHour

CVE-2019-7609

KEV PoC large

Prototype Pollution RCE in Elastic Kibana Timelion Visualizer

CISA: Kibana Arbitrary Code Execution

CVSS 3.1
10.0 critical
EPSS
95%p100
Published
()
KEV added
AI analysis

CVE-2019-7609 is an arbitrary code execution flaw in the Timelion visualizer of Elastic Kibana, a JavaScript injection flaw (CWE-94) driven by prototype pollution. An attacker with access to the Timelion application can send a crafted request that executes JavaScript, potentially leading to arbitrary commands running on the host with the permissions of the Kibana process. All Kibana releases before 5.6.15 and before 6.6.1 are affected, and the flaw also applies to the Kibana component bundled with Red Hat OpenShift Container Platform. Exploitation requires only network access to a vulnerable Timelion endpoint, making internet-exposed or broadly shared Kibana instances the primary targets. The flaw is actively exploited: it was added to CISA's Known Exploited Vulnerabilities catalog on 2022-01-10, carries a 95.3% EPSS score, and is among the top flaws recently leveraged by Russia-linked APT29 hackers against critical infrastructure according to recent US/UK advisories.

What to do: Upgrade Kibana to 5.6.15 or later (5.x) or 6.6.1 or later (6.x) per Elastic's instructions, and apply Red Hat's updated logging/Kibana packages for OpenShift. As interim mitigation, restrict access to the Timelion application, especially on internet-facing Kibana instances, and hunt for unexpected child processes or outbound connections spawned by the Kibana service indicating exploitation. Prioritize patching anything listed as internet-exposed, given the flaw's presence in CISA KEV and documented APT29 use.

Affected
elastic kibanaAll versions before 5.6.15 (5.x) and all versions before 6.6.1 (6.x)
redhat openshift container platform
Estimated exposure
largetens of thousands of internet-exposed Kibana instances (roughly 30,000-50,000 in public scans), with far more internal deployments — Internet-wide scan services have historically indexed tens of thousands of exposed Kibana instances, and the Elastic Stack's very broad enterprise adoption implies many additional internal deployments, though only instances reachable by…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Kibana versions before 5.6.15 and 6.6.1 contain an arbitrary code execution flaw in the Timelion visualizer. An attacker with access to the Timelion application could send a request that will attempt to execute javascript code. This could possibly lead to an attacker executing arbitrary commands with permissions of the Kibana process on the host system.

CISA Known Exploited Vulnerability
Affected
Elastic Kibana
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
elasticredhat
Products
kibana, openshift container platform
Weakness
CWE-94
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

In the news