{"id":"CVE-2024-37287","summary":"Kibana arbitrary code execution via prototype pollution","details":"A flaw allowing arbitrary code execution was discovered in Kibana. An attacker with access to ML and Alerting connector features, as well as write access to internal ML indices can trigger a prototype pollution vulnerability, ultimately leading to arbitrary code execution.","modified":"2026-08-12T15:15:18.721225Z","published":"2024-08-13T11:33:45.520Z","database_specific":{"cna_assigner":"elastic","cwe_ids":["CWE-94"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/37xxx/CVE-2024-37287.json","unresolved_ranges":[{"extracted_events":[{"introduced":"7.7.0, 8.0.0"},{"fixed":"7.17.23, 8.14.2"}],"source":"AFFECTED_FIELD"}]},"references":[{"type":"WEB","url":"https://discuss.elastic.co/t/kibana-8-14-2-7-17-23-security-update-esa-2024-22/"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/37xxx/CVE-2024-37287.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-37287"},{"type":"PACKAGE","url":"https://github.com/elastic/kibana"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/elastic/elasticsearch","events":[{"introduced":"81a1e9eda8e6183f5237786246f6dced26a10eaf"},{"fixed":"61d76462eecaf09ada684d1b5d319b5ff6865a83"},{"introduced":"1b6a7ece17463df5ff54a3e1302d825889aa1161"},{"fixed":"2afe7caceec8a26ff53817e5ed88235e90592a1b"}],"database_specific":{"cpe":"cpe:2.3:a:elastic:kibana:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"7.7.0"},{"fixed":"7.17.23"},{"introduced":"8.0.0"},{"fixed":"8.14.2"}],"source":"CPE_RANGE"}}],"database_specific":{"vanir_signatures":[{"deprecated":false,"digest":{"length":208,"function_hash":"157760494053827667837118573639039555464"},"id":"CVE-2024-37287-1aaca071","signature_type":"Function","signature_version":"v1","source":"https://github.com/elastic/elasticsearch/commit/2afe7caceec8a26ff53817e5ed88235e90592a1b","target":{"file":"x-pack/plugin/profiling/src/main/java/org/elasticsearch/xpack/profiling/action/HostMetadata.java","function":"HostMetadata"}},{"signature_type":"Line","signature_version":"v1","source":"https://github.com/elastic/elasticsearch/commit/2afe7caceec8a26ff53817e5ed88235e90592a1b","target":{"file":"x-pack/plugin/profiling/src/main/java/org/elasticsearch/xpack/profiling/action/HostMetadata.java"},"deprecated":false,"digest":{"threshold":0.9,"line_hashes":["193896757828941243145844563929241691184","39740713853991130670304049919892173951","254635273340976470161436700641393198580","22813550668332820745376567044791137889","305120663579770874905624609675087589553","317751899246233353377722397317280756073"]},"id":"CVE-2024-37287-3ed4fce0"},{"source":"https://github.com/elastic/elasticsearch/commit/61d76462eecaf09ada684d1b5d319b5ff6865a83","target":{"file":"qa/os/src/test/java/org/elasticsearch/packaging/test/DockerTests.java","function":"test600Interrupt"},"deprecated":false,"digest":{"function_hash":"69844453905830246677820397096534298013","length":935},"id":"CVE-2024-37287-3fa86dc6","signature_type":"Function","signature_version":"v1"},{"signature_version":"v1","source":"https://github.com/elastic/elasticsearch/commit/2afe7caceec8a26ff53817e5ed88235e90592a1b","target":{"file":"x-pack/plugin/profiling/src/test/java/org/elasticsearch/xpack/profiling/action/CO2CalculatorTests.java"},"deprecated":false,"digest":{"line_hashes":["62207153923184484221203502965514732534","130998578839398306062437037584016935344","132774376564083153220369201262182294846"],"threshold":0.9},"id":"CVE-2024-37287-4c266fcc","signature_type":"Line"},{"id":"CVE-2024-37287-bda6ba2f","signature_type":"Line","signature_version":"v1","source":"https://github.com/elastic/elasticsearch/commit/61d76462eecaf09ada684d1b5d319b5ff6865a83","target":{"file":"qa/os/src/test/java/org/elasticsearch/packaging/test/DockerTests.java"},"deprecated":false,"digest":{"line_hashes":["268439700297186282373755313812072452487","26797522030344409565822344236984547088","49674375891833826585064844018322645796","241861009769944274883436754269135918658","110241150124042836880806124194125742521","4974205076996931494879974579405987532"],"threshold":0.9}}],"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-37287.json","vanir_signatures_modified":"2026-08-12T15:15:18Z"}},{"ranges":[{"type":"GIT","repo":"https://github.com/elastic/kibana","events":[{"introduced":"e13d5b1fed429df03e29af259ffccd6453250947"},{"fixed":"89cafc519e1d6e0e08d8cf5c13eee6886fe6e412"},{"introduced":"57ca5e139a33dd2eed927ce98d8231a1f217cd15"},{"fixed":"50d89958910ab6fa9b8c4f4f40c53e89ad6dbbe1"}],"database_specific":{"cpe":"cpe:2.3:a:elastic:kibana:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"7.7.0"},{"fixed":"7.17.23"},{"introduced":"8.0.0"},{"fixed":"8.14.2"}],"source":"CPE_RANGE"}}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-37287.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H"}]}