NOMISEC-mpgn/CVE-2019-7609

NOMISEC WORKING POC
Exploit for CVE-2019-7609 - Kibana Timelion Prototype Pollution RCE
AI Analysis

This repository contains a working proof-of-concept exploit for CVE-2019-7609, a prototype pollution vulnerability in Kibana's Timelion visualizer. The exploit leverages JavaScript payloads to achieve remote code execution (RCE) by manipulating the prototype chain and executing arbitrary commands via Node.js child_process.

Attack Type
RCE
Complexity
moderate
Reliability
reliable
MITRE ATT&CK
T1059 - Command and Scripting Interpreter T1190 - Exploit Public-Facing Application
Loading exploit code...
Download ZIP Password: eip
Source
Platform Nomisec
Type remote-auth
Files 2
Stars 56
Forks 12
Last Push Dec 20, 2019
Vulnerability
CVE-2019-7609
Kibana Timelion Prototype Pollution RCE
CRITICAL KEV
CVSS 10.0