CVE-2019-7609
KEV PoC largePrototype Pollution RCE in Elastic Kibana Timelion Visualizer
CISA: Kibana Arbitrary Code Execution
CVE-2019-7609 is an arbitrary code execution flaw in the Timelion visualizer of Elastic Kibana, a JavaScript injection flaw (CWE-94) driven by prototype pollution. An attacker with access to the Timelion application can send a crafted request that executes JavaScript, potentially leading to arbitrary commands running on the host with the permissions of the Kibana process. All Kibana releases before 5.6.15 and before 6.6.1 are affected, and the flaw also applies to the Kibana component bundled with Red Hat OpenShift Container Platform. Exploitation requires only network access to a vulnerable Timelion endpoint, making internet-exposed or broadly shared Kibana instances the primary targets. The flaw is actively exploited: it was added to CISA's Known Exploited Vulnerabilities catalog on 2022-01-10, carries a 95.3% EPSS score, and is among the top flaws recently leveraged by Russia-linked APT29 hackers against critical infrastructure according to recent US/UK advisories.
What to do: Upgrade Kibana to 5.6.15 or later (5.x) or 6.6.1 or later (6.x) per Elastic's instructions, and apply Red Hat's updated logging/Kibana packages for OpenShift. As interim mitigation, restrict access to the Timelion application, especially on internet-facing Kibana instances, and hunt for unexpected child processes or outbound connections spawned by the Kibana service indicating exploitation. Prioritize patching anything listed as internet-exposed, given the flaw's presence in CISA KEV and documented APT29 use.
| elastic kibana | All versions before 5.6.15 (5.x) and all versions before 6.6.1 (6.x) |
| redhat openshift container platform | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Kibana versions before 5.6.15 and 6.6.1 contain an arbitrary code execution flaw in the Timelion visualizer. An attacker with access to the Timelion application could send a request that will attempt to execute javascript code. This could possibly lead to an attacker executing arbitrary commands with permissions of the Kibana process on the host system.
- Affected
- Elastic Kibana
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Unknown