Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:25606
HistoryJun 04, 2020 - 6:34 a.m.

Prototype Pollution

2020-06-0406:34:05
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
17

0.001 Low

EPSS

Percentile

39.4%

kibana is vulnerable to prototype pollution. The vulnerability exists due to an improper use of Object.keys, allowing an authenticated user with Kibana index writing privilege to overwrite Object.prototype and execute malicious code with the permissions of the Kibana process on the host.

CPENameOperatorVersion
kibanale7.6.2
kibanale6.8.8

0.001 Low

EPSS

Percentile

39.4%