CVE-2020-7013

HIGH

Kibana < 6.8.9 - Authenticated Remote Code Execution via TSVB Visualization

Title source: llm
STIX 2.1

Description

Kibana versions before 6.8.9 and 7.7.0 contain a prototype pollution flaw in TSVB. An authenticated attacker with privileges to create TSVB visualizations could insert data that would cause Kibana to execute arbitrary code. This could possibly lead to an attacker executing code with the permissions of the Kibana process on the host system.

References (1)

Core 1
Core References
Vendor Advisory x_refsource_misc
https://www.elastic.co/community/security/

Scores

CVSS v3 7.2
EPSS 0.0137
EPSS Percentile 80.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-94
Status published
Products (3)
elastic/kibana < 6.8.9
redhat/openshift_container_platform 3.11
redhat/openshift_container_platform 4.0
Published Jun 03, 2020
Tracked Since Feb 18, 2026