CVE-2019-7618

MEDIUM

Elastic Code <7.3.2 - Info Disclosure

Title source: llm
STIX 2.1

Description

A local file disclosure flaw was found in Elastic Code versions 7.3.0, 7.3.1, and 7.3.2. If a malicious code repository is imported into Code it is possible to read arbitrary files from the local filesystem of the Kibana instance running Code with the permission of the Kibana system user.

Scores

CVSS v3 6.5
EPSS 0.0021
EPSS Percentile 43.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Details

CWE
CWE-22 CWE-538
Status published
Products (3)
elastic/kibana 7.3.0
elastic/kibana 7.3.1
elastic/kibana 7.3.2
Published Oct 01, 2019
Tracked Since Feb 18, 2026