Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:13543
HistoryMar 26, 2019 - 4:06 a.m.

Arbitrary Code Execution

2019-03-2604:06:20
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
12

0.01 Low

EPSS

Percentile

84.1%

kibana is vulnerable to arbitrary code execution. The vulnerability exists due to a flaw which allows an attacker to send a malicious request to execute Javascript code since xpack.security.audit.enabled in the kibana.yml is set to true by default, leading to arbitrary code execution on the host system.