{"id":"CVE-2019-7609","details":"Kibana versions before 5.6.15 and 6.6.1 contain an arbitrary code execution flaw in the Timelion visualizer. An attacker with access to the Timelion application could send a request that will attempt to execute javascript code. This could possibly lead to an attacker executing arbitrary commands with permissions of the Kibana process on the host system.","modified":"2026-07-08T05:53:29.385040349Z","published":"2019-03-25T19:29:02.147Z","database_specific":{"unresolved_ranges":[{"source":"CPE_STRING","vendor_product":"redhat:openshift_container_platform","cpes":["cpe:2.3:a:redhat:openshift_container_platform:3.11:*:*:*:*:*:*:*","cpe:2.3:a:redhat:openshift_container_platform:4.1:*:*:*:*:*:*:*"],"extracted_events":[{"introduced":"3.11"},{"last_affected":"3.11"},{"introduced":"4.1"},{"last_affected":"4.1"}]}]},"references":[{"type":"WEB","url":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2019-7609"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHBA-2019:2824"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2019:2860"},{"type":"ADVISORY","url":"https://discuss.elastic.co/t/elastic-stack-6-6-1-and-5-6-15-security-update/169077"},{"type":"ADVISORY","url":"https://www.elastic.co/community/security"},{"type":"EVIDENCE","url":"http://packetstormsecurity.com/files/174569/Kibana-Timelion-Prototype-Pollution-Remote-Code-Execution.html"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/elastic/elasticsearch","events":[{"introduced":"0"},{"fixed":"fe7575a32e23e15e0a77677dc1a180206554228b"},{"introduced":"8f0685b924b9159807704ec2593b26e28105da44"},{"fixed":"1fd8f691bf2e467057b864eea9103a6e3345af3e"}],"database_specific":{"cpe":"cpe:2.3:a:elastic:kibana:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"fixed":"5.6.15"},{"introduced":"6.0.0"},{"fixed":"6.6.1"}],"source":"CPE_RANGE"}}],"versions":["v6.6.0","v5.6.14","v5.6.13","v5.6.12","v5.6.11","v5.6.10","v5.6.9","v5.6.8","v5.6.7","v5.6.6","v5.6.5","v5.6.4","v5.6.3","v5.6.2","v5.6.1","v5.6.0","v6.0.0-alpha2","v6.0.0-alpha1","v5.0.0-alpha5","v1.0.0.RC1","v1.0.0.Beta2","v1.0.0.Beta1","v0.90.0","v0.90.0.RC2","v0.90.0.RC1","v0.90.0.Beta1","v0.20.0.RC1","v0.19.0","v0.19.0.RC3","v0.19.0.RC2","v0.19.0.RC1","v0.18.0","v0.17.0","v0.16.0","v0.15.0","v0.14.0","v0.13.0","v0.12.0","v0.11.0","v0.10.0","v0.9.0","v0.8.0","v0.7.1","v0.7.0","v0.6.0","v0.5.1","v0.5.0","v0.4.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2019-7609.json"}},{"ranges":[{"type":"GIT","repo":"https://github.com/elastic/kibana","events":[{"introduced":"0"},{"fixed":"e4f1e8f824c4cdc70bfa09a5ec734d7108366456"},{"introduced":"f8bc449f5a6b28d0597730b1cf03fefe7e33422e"},{"fixed":"c0c81857d435f499ec2514d9a4823e3dc87021bd"}],"database_specific":{"cpe":"cpe:2.3:a:elastic:kibana:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"fixed":"5.6.15"},{"introduced":"6.0.0"},{"fixed":"6.6.1"}],"source":"CPE_RANGE"}}],"versions":["v6.6.0","v5.6.14","v5.6.13","v5.6.12","v5.6.11","v5.6.10","v5.6.8","v5.6.7","v5.6.6","v5.6.5","v5.6.4","v5.6.3","v5.6.2","v5.6.1","v5.6.0","v6.0.0-alpha2","v6.0.0-alpha1","v5.0.0-alpha5","v4.2.0-beta1","v4.0.0-beta3","v4.0.0-beta2","v4.0.0-beta1.1","v4.0.0-beta1"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2019-7609.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H"}]}