CVE-2019-7618

MEDIUM

Elastic Code <7.3.2 - Info Disclosure

Title source: llm
STIX 2.1

Description

A local file disclosure flaw was found in Elastic Code versions 7.3.0, 7.3.1, and 7.3.2. If a malicious code repository is imported into Code it is possible to read arbitrary files from the local filesystem of the Kibana instance running Code with the permission of the Kibana system user.

References (2)

Core 2
Core References
Permissions Required, Vendor Advisory x_refsource_misc
https://staging-website.elastic.co/community/security
Release Notes, Vendor Advisory x_refsource_misc
https://discuss.elastic.co/t/elastic-stack-7-4-0-security-update/201831

Scores

CVSS v3 6.5
EPSS 0.0145
EPSS Percentile 69.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Details

CWE
CWE-22 CWE-538
Status published
Products (3)
elastic/kibana 7.3.0
elastic/kibana 7.3.1
elastic/kibana 7.3.2
Published Oct 01, 2019
Tracked Since Feb 18, 2026