{"id":"CVE-2020-7013","details":"Kibana versions before 6.8.9 and 7.7.0 contain a prototype pollution flaw in TSVB. An authenticated attacker with privileges to create TSVB visualizations could insert data that would cause Kibana to execute arbitrary code. This could possibly lead to an attacker executing code with the permissions of the Kibana process on the host system.","modified":"2026-07-08T20:29:32.269954Z","published":"2020-06-03T18:15:22.963Z","database_specific":{"unresolved_ranges":[{"vendor_product":"redhat:openshift_container_platform","cpes":["cpe:2.3:a:redhat:openshift_container_platform:3.11:*:*:*:*:*:*:*","cpe:2.3:a:redhat:openshift_container_platform:4.0:*:*:*:*:*:*:*"],"extracted_events":[{"introduced":"3.11"},{"last_affected":"3.11"},{"introduced":"4.0"},{"last_affected":"4.0"}],"source":"CPE_STRING"}]},"references":[{"type":"ADVISORY","url":"https://www.elastic.co/community/security/"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/elastic/elasticsearch","events":[{"introduced":"0"},{"fixed":"be2c7bf0f8427387e84c68ad8d2d9abbc60a64da"},{"introduced":"b7e28a7232616c7a21bc879a535d801b8553ba77"},{"fixed":"81a1e9eda8e6183f5237786246f6dced26a10eaf"}],"database_specific":{"cpe":"cpe:2.3:a:elastic:kibana:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"fixed":"6.8.9"},{"introduced":"7.0.0"},{"fixed":"7.7.0"}],"source":"CPE_RANGE"}}],"versions":["v6.8.8","v6.8.7","v6.8.6","v6.8.5","v6.8.4","v6.8.3","v6.8.2","v6.8.1","v6.8.0","v6.7.2","v6.7.1","v6.7.0","v7.0.0-alpha2","v7.0.0-alpha1","v6.0.0-alpha2","v6.0.0-alpha1","v1.0.0.RC1","v1.0.0.Beta2","v1.0.0.Beta1","v0.90.0","v0.90.0.RC2","v0.90.0.RC1","v0.90.0.Beta1","v0.20.0.RC1","v0.19.0","v0.19.0.RC3","v0.19.0.RC2","v0.19.0.RC1","v0.18.0","v0.17.0","v0.16.0","v0.15.0","v0.14.0","v0.13.0","v0.12.0","v0.11.0","v0.10.0","v0.9.0","v0.8.0","v0.7.1","v0.7.0","v0.6.0","v0.5.1","v0.5.0","v0.4.0"],"database_specific":{"vanir_signatures_modified":"2026-07-08T20:29:32Z","vanir_signatures":[{"digest":{"line_hashes":["45579179051866194117804149996246200604","119848415071729397178158796374652642141","268702904613209701760138481469986520807","233930455696044821969899735660498823702","163890961310343880460845341215056522543","121781746028062861453040104154954910898","75515967174573794578045725915657184459","242265910704563585451341748271450313521"],"threshold":0.9},"id":"CVE-2020-7013-46d0a062","signature_type":"Line","signature_version":"v1","source":"https://github.com/elastic/elasticsearch/commit/be2c7bf0f8427387e84c68ad8d2d9abbc60a64da","target":{"file":"x-pack/plugin/ccr/src/test/java/org/elasticsearch/xpack/CcrIntegTestCase.java"},"deprecated":false},{"signature_type":"Line","signature_version":"v1","source":"https://github.com/elastic/elasticsearch/commit/be2c7bf0f8427387e84c68ad8d2d9abbc60a64da","target":{"file":"x-pack/plugin/ccr/src/test/java/org/elasticsearch/xpack/ccr/RestartIndexFollowingIT.java"},"deprecated":false,"digest":{"line_hashes":["224199583765534546450572128505726274014","323492397107490477775877295489877472566","277068975507872740214400598145450029935","254138046711047538847606693125357275743","206429083783286640014169218886022315638","296895094182996624815457633142985022277","253279550837581745573429071920825148529"],"threshold":0.9},"id":"CVE-2020-7013-5fe7f71b"},{"target":{"file":"test/framework/src/main/java/org/elasticsearch/test/InternalSettingsPlugin.java"},"deprecated":false,"digest":{"line_hashes":["86059810673072489087777826235705304512","113362693214779684611162611810226256967","43697961644316964677784293423168194536","41532001999738243291277523044268874425","194352752720767127991353649794071543700","26922355690411780912727066379262132323","162660476306345741350731046397728999646","42609840016367210804582075884021165578"],"threshold":0.9},"id":"CVE-2020-7013-631a6c07","signature_type":"Line","signature_version":"v1","source":"https://github.com/elastic/elasticsearch/commit/be2c7bf0f8427387e84c68ad8d2d9abbc60a64da"},{"source":"https://github.com/elastic/elasticsearch/commit/be2c7bf0f8427387e84c68ad8d2d9abbc60a64da","target":{"file":"server/src/main/java/org/elasticsearch/transport/RemoteClusterConnection.java"},"deprecated":false,"digest":{"line_hashes":["174040409401571725204720260102635061022","16187474032464237735691424023377353787","157325855902521259613194453628253345659","125845012298588357729943994413230245880","179070855604691138673792169908461853070","244686288359459323752717883005506982217","16206305364527329158402936318262269038","22120711428700509694655039935643773956","162142159011466565104666201381501521296","208975523842519538430290185568227031035","20125575360198518227008405448322384310","7851914447724541572199970193489442946","232412995254253867961617868910148443499","277652103959366784875739196726273869212","260602594023334785138478392292505235222","322400565104534255612132955586742153456","298859253154070104971610918767332865517","71632434484998290779628851355352485598","91838529997363223439127131957701479124","289813517270842779401675180076750458091","202038932232099387720964798180556002825","39906778269268557586257234953299656025","140668071508320775811985736868996745913","198576572049694124173774252374230243369"],"threshold":0.9},"id":"CVE-2020-7013-763aad9c","signature_type":"Line","signature_version":"v1"},{"digest":{"length":743,"function_hash":"200263057186406267777659938741382370028"},"id":"CVE-2020-7013-cdc38740","signature_type":"Function","signature_version":"v1","source":"https://github.com/elastic/elasticsearch/commit/be2c7bf0f8427387e84c68ad8d2d9abbc60a64da","target":{"file":"server/src/main/java/org/elasticsearch/transport/RemoteClusterConnection.java","function":"RemoteClusterConnection"},"deprecated":false},{"signature_version":"v1","source":"https://github.com/elastic/elasticsearch/commit/be2c7bf0f8427387e84c68ad8d2d9abbc60a64da","target":{"file":"x-pack/plugin/ccr/src/test/java/org/elasticsearch/xpack/ccr/CcrRetentionLeaseIT.java"},"deprecated":false,"digest":{"line_hashes":["208231173717578920429253189869714737202","88008018763437278132911345558306380065","44084908447052032805700862068250436233","134469572131951082585105400923879610884"],"threshold":0.9},"id":"CVE-2020-7013-d16234d1","signature_type":"Line"},{"digest":{"function_hash":"221701719401787106419630928689580688352","length":188},"id":"CVE-2020-7013-ddf385fa","signature_type":"Function","signature_version":"v1","source":"https://github.com/elastic/elasticsearch/commit/be2c7bf0f8427387e84c68ad8d2d9abbc60a64da","target":{"file":"x-pack/plugin/ccr/src/test/java/org/elasticsearch/xpack/ccr/CcrRetentionLeaseIT.java","function":"followerClusterSettings"},"deprecated":false},{"target":{"file":"test/framework/src/main/java/org/elasticsearch/test/InternalSettingsPlugin.java","function":"getSettings"},"deprecated":false,"digest":{"length":338,"function_hash":"302264429194571615229087144455490955214"},"id":"CVE-2020-7013-f452c8f3","signature_type":"Function","signature_version":"v1","source":"https://github.com/elastic/elasticsearch/commit/be2c7bf0f8427387e84c68ad8d2d9abbc60a64da"}],"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2020-7013.json"}},{"ranges":[{"type":"GIT","repo":"https://github.com/elastic/kibana","events":[{"introduced":"0"},{"fixed":"f287f702223d72e963bf7ea663b89868fec88e11"},{"introduced":"ee89fda8a17eff9c93f7400c102edf76cb4d7d8a"},{"fixed":"e13d5b1fed429df03e29af259ffccd6453250947"}],"database_specific":{"cpe":"cpe:2.3:a:elastic:kibana:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"fixed":"6.8.9"},{"introduced":"7.0.0"},{"fixed":"7.7.0"}],"source":"CPE_RANGE"}}],"versions":["v6.8.8","v6.8.7","v6.8.6","v6.8.5","v6.8.4","v6.8.3","v6.8.2","v6.8.1","v6.8.0","v6.7.2","v6.7.1","v6.7.0","v7.0.0-alpha2","v7.0.0-alpha1","7.0-known-good","v6.0.0-alpha2","v6.0.0-alpha1","v5.0.0-alpha5","v4.2.0-beta1","v4.0.0-beta3","v4.0.0-beta2","v4.0.0-beta1.1","v4.0.0-beta1"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2020-7013.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"}]}