Back

CRITICAL

kibana: Audit logging Remote Code Execution issue

Published Mar 25, 2019

Description

Kibana versions before 6.6.1 contain an arbitrary code execution flaw in the security audit logger. If a Kibana instance has the setting xpack.security.audit.enabled set to true, an attacker could send a request that will attempt to execute javascript code. This could possibly lead to an attacker executing arbitrary commands with permissions of the Kibana process on the host system.

Affected products

Remediation

Red Hat statement

Red Hat OpenStack Platform 8.0/9.0 Operational Tools Kibana/Elasticsearch versions do not include nor support X-Pack (8/9 versions must use the optional Shield, also not packaged); not affected. Red Hat OpenShift Container Platform 4.1, and 3.x do not install the vulnerable package (Shield for Kibana 4, and X-Pack for Kibana 5), so the impact is lowered to moderate.

Metrics

References (8)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner elastic
Published Mar 25, 2019
Updated Aug 4, 2024
Reserved Feb 7, 2019
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Important
Public date Feb 19, 2019