Lucene search

K
redhatcveRedhat.comRH:CVE-2018-17246
HistoryNov 07, 2018 - 9:19 a.m.

CVE-2018-17246

2018-11-0709:19:10
redhat.com
access.redhat.com
18

EPSS

0.963

Percentile

99.6%

Kibana, before 6.4.3 and 5.6.13, contain an arbitrary file inclusion flaw in the Console plugin. An attacker with access to the Kibana Console API could send a request that will attempt to execute JavaScript code. This could possibly lead to an attacker executing arbitrary commands with permissions of the Kibana process on the host system.

EPSS

0.963

Percentile

99.6%