Lucene search

K
redhatcveRedhat.comRH:CVE-2019-7610
HistoryApr 09, 2020 - 12:18 p.m.

CVE-2019-7610

2020-04-0912:18:10
redhat.com
access.redhat.com
13

0.01 Low

EPSS

Percentile

84.1%

An arbitrary code execution flaw was found in Kibana in versions prior to 5.6.15 and 6.6.1. If a Kibana instance has the setting xpack.security.audit.enabled set to true, an attacker could send a request that will attempt to execute javascript code. This could possibly lead to an attacker executing arbitrary commands with permissions of the Kibana process on the host system. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.