Kibana versions before 6.6.1 contain an arbitrary code execution flaw in the security audit logger. If a Kibana instance has the setting xpack.security.audit.enabled set to true, an attacker could send a request that will attempt to execute javascript code. This could possibly lead to an attacker executing arbitrary commands with permissions of the Kibana process on the host system.
Metrics
No CVSS v4.0
No CVSS v3.1
Attack Vector Network
Attack Complexity High
Privileges Required None
Scope Changed
Confidentiality Impact High
Integrity Impact High
Availability Impact High
User Interaction None
Access Vector Network
Access Complexity Medium
Authentication None
Confidentiality Impact Complete
Integrity Impact Complete
Availability Impact Complete
AV:N/AC:M/Au:N/C:C/I:C/A:C
This CVE is not in the KEV list.
Key SSVC decision points have not yet been added.
Affected Vendors & Products
Vendors | Products |
---|---|
Elastic |
|
Redhat |
|
Configuration 1 [-]
|
Package | CPE | Advisory | Released Date |
---|---|---|---|
Red Hat OpenShift Container Platform 3.11 | |||
openshift3/apb-base:v3.11.146-1 | cpe:/a:redhat:openshift:3.11::el7 | RHBA-2019:2824 | 2019-09-24T00:00:00Z |
openshift3/apb-tools:v3.11.146-1 | cpe:/a:redhat:openshift:3.11::el7 | RHBA-2019:2824 | 2019-09-24T00:00:00Z |
openshift3/automation-broker-apb:v3.11.146-1 | cpe:/a:redhat:openshift:3.11::el7 | RHBA-2019:2824 | 2019-09-24T00:00:00Z |
openshift3/csi-attacher:v3.11.146-2 | cpe:/a:redhat:openshift:3.11::el7 | RHBA-2019:2824 | 2019-09-24T00:00:00Z |
openshift3/csi-driver-registrar:v3.11.146-2 | cpe:/a:redhat:openshift:3.11::el7 | RHBA-2019:2824 | 2019-09-24T00:00:00Z |
openshift3/csi-livenessprobe:v3.11.146-2 | cpe:/a:redhat:openshift:3.11::el7 | RHBA-2019:2824 | 2019-09-24T00:00:00Z |
openshift3/csi-provisioner:v3.11.146-2 | cpe:/a:redhat:openshift:3.11::el7 | RHBA-2019:2824 | 2019-09-24T00:00:00Z |
openshift3/grafana:v3.11.146-2 | cpe:/a:redhat:openshift:3.11::el7 | RHBA-2019:2824 | 2019-09-24T00:00:00Z |
openshift3/jenkins-slave-base-rhel7:v3.11.146-1 | cpe:/a:redhat:openshift:3.11::el7 | RHBA-2019:2824 | 2019-09-24T00:00:00Z |
openshift3/jenkins-slave-maven-rhel7:v3.11.146-1 | cpe:/a:redhat:openshift:3.11::el7 | RHBA-2019:2824 | 2019-09-24T00:00:00Z |
openshift3/jenkins-slave-nodejs-rhel7:v3.11.146-1 | cpe:/a:redhat:openshift:3.11::el7 | RHBA-2019:2824 | 2019-09-24T00:00:00Z |
openshift3/local-storage-provisioner:v3.11.146-1 | cpe:/a:redhat:openshift:3.11::el7 | RHBA-2019:2824 | 2019-09-24T00:00:00Z |
openshift3/logging-fluentd:v3.11.146-4 | cpe:/a:redhat:openshift:3.11::el7 | RHBA-2019:2824 | 2019-09-24T00:00:00Z |
openshift3/manila-provisioner:v3.11.146-2 | cpe:/a:redhat:openshift:3.11::el7 | RHBA-2019:2824 | 2019-09-24T00:00:00Z |
openshift3/mariadb-apb:v3.11.146-2 | cpe:/a:redhat:openshift:3.11::el7 | RHBA-2019:2824 | 2019-09-24T00:00:00Z |
openshift3/mediawiki:v3.11.146-1 | cpe:/a:redhat:openshift:3.11::el7 | RHBA-2019:2824 | 2019-09-24T00:00:00Z |
openshift3/mediawiki-apb:v3.11.146-2 | cpe:/a:redhat:openshift:3.11::el7 | RHBA-2019:2824 | 2019-09-24T00:00:00Z |
openshift3/metrics-cassandra:v3.11.146-1 | cpe:/a:redhat:openshift:3.11::el7 | RHBA-2019:2824 | 2019-09-24T00:00:00Z |
openshift3/metrics-hawkular-metrics:v3.11.146-2 | cpe:/a:redhat:openshift:3.11::el7 | RHBA-2019:2824 | 2019-09-24T00:00:00Z |
openshift3/metrics-hawkular-openshift-agent:v3.11.146-2 | cpe:/a:redhat:openshift:3.11::el7 | RHBA-2019:2824 | 2019-09-24T00:00:00Z |
openshift3/metrics-heapster:v3.11.146-2 | cpe:/a:redhat:openshift:3.11::el7 | RHBA-2019:2824 | 2019-09-24T00:00:00Z |
openshift3/metrics-schema-installer:v3.11.146-1 | cpe:/a:redhat:openshift:3.11::el7 | RHBA-2019:2824 | 2019-09-24T00:00:00Z |
openshift3/mysql-apb:v3.11.146-2 | cpe:/a:redhat:openshift:3.11::el7 | RHBA-2019:2824 | 2019-09-24T00:00:00Z |
openshift3/node:v3.11.146-1 | cpe:/a:redhat:openshift:3.11::el7 | RHBA-2019:2824 | 2019-09-24T00:00:00Z |
openshift3/oauth-proxy:v3.11.146-2 | cpe:/a:redhat:openshift:3.11::el7 | RHBA-2019:2824 | 2019-09-24T00:00:00Z |
openshift3/ose:v3.11.146-1 | cpe:/a:redhat:openshift:3.11::el7 | RHBA-2019:2824 | 2019-09-24T00:00:00Z |
openshift3/ose-ansible:v3.11.146-3 | cpe:/a:redhat:openshift:3.11::el7 | RHBA-2019:2824 | 2019-09-24T00:00:00Z |
openshift3/ose-ansible-service-broker:v3.11.146-3 | cpe:/a:redhat:openshift:3.11::el7 | RHBA-2019:2824 | 2019-09-24T00:00:00Z |
openshift3/ose-cli:v3.11.146-2 | cpe:/a:redhat:openshift:3.11::el7 | RHBA-2019:2824 | 2019-09-24T00:00:00Z |
openshift3/ose-cluster-autoscaler:v3.11.146-2 | cpe:/a:redhat:openshift:3.11::el7 | RHBA-2019:2824 | 2019-09-24T00:00:00Z |
openshift3/ose-cluster-capacity:v3.11.146-2 | cpe:/a:redhat:openshift:3.11::el7 | RHBA-2019:2824 | 2019-09-24T00:00:00Z |
openshift3/ose-cluster-monitoring-operator:v3.11.146-2 | cpe:/a:redhat:openshift:3.11::el7 | RHBA-2019:2824 | 2019-09-24T00:00:00Z |
openshift3/ose-configmap-reloader:v3.11.146-1 | cpe:/a:redhat:openshift:3.11::el7 | RHBA-2019:2824 | 2019-09-24T00:00:00Z |
openshift3/ose-console:v3.11.146-1 | cpe:/a:redhat:openshift:3.11::el7 | RHBA-2019:2824 | 2019-09-24T00:00:00Z |
openshift3/ose-control-plane:v3.11.146-1 | cpe:/a:redhat:openshift:3.11::el7 | RHBA-2019:2824 | 2019-09-24T00:00:00Z |
openshift3/ose-deployer:v3.11.146-1 | cpe:/a:redhat:openshift:3.11::el7 | RHBA-2019:2824 | 2019-09-24T00:00:00Z |
openshift3/ose-descheduler:v3.11.146-2 | cpe:/a:redhat:openshift:3.11::el7 | RHBA-2019:2824 | 2019-09-24T00:00:00Z |
openshift3/ose-docker-builder:v3.11.146-1 | cpe:/a:redhat:openshift:3.11::el7 | RHBA-2019:2824 | 2019-09-24T00:00:00Z |
openshift3/ose-docker-registry:v3.11.146-2 | cpe:/a:redhat:openshift:3.11::el7 | RHBA-2019:2824 | 2019-09-24T00:00:00Z |
openshift3/ose-efs-provisioner:v3.11.146-3 | cpe:/a:redhat:openshift:3.11::el7 | RHBA-2019:2824 | 2019-09-24T00:00:00Z |
openshift3/ose-egress-dns-proxy:v3.11.146-2 | cpe:/a:redhat:openshift:3.11::el7 | RHBA-2019:2824 | 2019-09-24T00:00:00Z |
openshift3/ose-egress-http-proxy:v3.11.146-2 | cpe:/a:redhat:openshift:3.11::el7 | RHBA-2019:2824 | 2019-09-24T00:00:00Z |
openshift3/ose-egress-router:v3.11.146-2 | cpe:/a:redhat:openshift:3.11::el7 | RHBA-2019:2824 | 2019-09-24T00:00:00Z |
openshift3/ose-haproxy-router:v3.11.146-1 | cpe:/a:redhat:openshift:3.11::el7 | RHBA-2019:2824 | 2019-09-24T00:00:00Z |
openshift3/ose-hyperkube:v3.11.146-2 | cpe:/a:redhat:openshift:3.11::el7 | RHBA-2019:2824 | 2019-09-24T00:00:00Z |
openshift3/ose-hypershift:v3.11.146-2 | cpe:/a:redhat:openshift:3.11::el7 | RHBA-2019:2824 | 2019-09-24T00:00:00Z |
openshift3/ose-keepalived-ipfailover:v3.11.146-2 | cpe:/a:redhat:openshift:3.11::el7 | RHBA-2019:2824 | 2019-09-24T00:00:00Z |
openshift3/ose-kube-rbac-proxy:v3.11.146-1 | cpe:/a:redhat:openshift:3.11::el7 | RHBA-2019:2824 | 2019-09-24T00:00:00Z |
openshift3/ose-kube-state-metrics:v3.11.146-1 | cpe:/a:redhat:openshift:3.11::el7 | RHBA-2019:2824 | 2019-09-24T00:00:00Z |
openshift3/ose-logging-curator5:v3.11.146-5 | cpe:/a:redhat:openshift:3.11::el7 | RHBA-2019:2824 | 2019-09-24T00:00:00Z |
openshift3/ose-logging-elasticsearch5:v3.11.146-4 | cpe:/a:redhat:openshift:3.11::el7 | RHBA-2019:2824 | 2019-09-24T00:00:00Z |
openshift3/ose-logging-eventrouter:v3.11.146-4 | cpe:/a:redhat:openshift:3.11::el7 | RHBA-2019:2824 | 2019-09-24T00:00:00Z |
openshift3/ose-logging-fluentd:v3.11.146-4 | cpe:/a:redhat:openshift:3.11::el7 | RHBA-2019:2824 | 2019-09-24T00:00:00Z |
openshift3/ose-logging-kibana5:v3.11.146-6 | cpe:/a:redhat:openshift:3.11::el7 | RHBA-2019:2824 | 2019-09-24T00:00:00Z |
openshift3/ose-metrics-cassandra:v3.11.146-1 | cpe:/a:redhat:openshift:3.11::el7 | RHBA-2019:2824 | 2019-09-24T00:00:00Z |
openshift3/ose-metrics-hawkular-metrics:v3.11.146-2 | cpe:/a:redhat:openshift:3.11::el7 | RHBA-2019:2824 | 2019-09-24T00:00:00Z |
openshift3/ose-metrics-hawkular-openshift-agent:v3.11.146-2 | cpe:/a:redhat:openshift:3.11::el7 | RHBA-2019:2824 | 2019-09-24T00:00:00Z |
openshift3/ose-metrics-heapster:v3.11.146-2 | cpe:/a:redhat:openshift:3.11::el7 | RHBA-2019:2824 | 2019-09-24T00:00:00Z |
openshift3/ose-metrics-schema-installer:v3.11.146-1 | cpe:/a:redhat:openshift:3.11::el7 | RHBA-2019:2824 | 2019-09-24T00:00:00Z |
openshift3/ose-metrics-server:v3.11.146-1 | cpe:/a:redhat:openshift:3.11::el7 | RHBA-2019:2824 | 2019-09-24T00:00:00Z |
openshift3/ose-node:v3.11.146-1 | cpe:/a:redhat:openshift:3.11::el7 | RHBA-2019:2824 | 2019-09-24T00:00:00Z |
openshift3/ose-node-problem-detector:v3.11.146-2 | cpe:/a:redhat:openshift:3.11::el7 | RHBA-2019:2824 | 2019-09-24T00:00:00Z |
openshift3/ose-operator-lifecycle-manager:v3.11.146-2 | cpe:/a:redhat:openshift:3.11::el7 | RHBA-2019:2824 | 2019-09-24T00:00:00Z |
openshift3/ose-ovn-kubernetes:v3.11.146-1 | cpe:/a:redhat:openshift:3.11::el7 | RHBA-2019:2824 | 2019-09-24T00:00:00Z |
openshift3/ose-pod:v3.11.146-2 | cpe:/a:redhat:openshift:3.11::el7 | RHBA-2019:2824 | 2019-09-24T00:00:00Z |
openshift3/ose-prometheus-config-reloader:v3.11.146-2 | cpe:/a:redhat:openshift:3.11::el7 | RHBA-2019:2824 | 2019-09-24T00:00:00Z |
openshift3/ose-prometheus-operator:v3.11.146-2 | cpe:/a:redhat:openshift:3.11::el7 | RHBA-2019:2824 | 2019-09-24T00:00:00Z |
openshift3/ose-recycler:v3.11.146-1 | cpe:/a:redhat:openshift:3.11::el7 | RHBA-2019:2824 | 2019-09-24T00:00:00Z |
openshift3/ose-service-catalog:v3.11.146-2 | cpe:/a:redhat:openshift:3.11::el7 | RHBA-2019:2824 | 2019-09-24T00:00:00Z |
openshift3/ose-template-service-broker:v3.11.146-2 | cpe:/a:redhat:openshift:3.11::el7 | RHBA-2019:2824 | 2019-09-24T00:00:00Z |
openshift3/ose-tests:v3.11.146-1 | cpe:/a:redhat:openshift:3.11::el7 | RHBA-2019:2824 | 2019-09-24T00:00:00Z |
openshift3/ose-web-console:v3.11.146-2 | cpe:/a:redhat:openshift:3.11::el7 | RHBA-2019:2824 | 2019-09-24T00:00:00Z |
openshift3/postgresql-apb:v3.11.146-2 | cpe:/a:redhat:openshift:3.11::el7 | RHBA-2019:2824 | 2019-09-24T00:00:00Z |
openshift3/prometheus:v3.11.146-2 | cpe:/a:redhat:openshift:3.11::el7 | RHBA-2019:2824 | 2019-09-24T00:00:00Z |
openshift3/prometheus-alertmanager:v3.11.146-2 | cpe:/a:redhat:openshift:3.11::el7 | RHBA-2019:2824 | 2019-09-24T00:00:00Z |
openshift3/prometheus-node-exporter:v3.11.146-2 | cpe:/a:redhat:openshift:3.11::el7 | RHBA-2019:2824 | 2019-09-24T00:00:00Z |
openshift3/registry-console:v3.11.146-1 | cpe:/a:redhat:openshift:3.11::el7 | RHBA-2019:2824 | 2019-09-24T00:00:00Z |
openshift3/snapshot-controller:v3.11.146-2 | cpe:/a:redhat:openshift:3.11::el7 | RHBA-2019:2824 | 2019-09-24T00:00:00Z |
openshift3/snapshot-provisioner:v3.11.146-2 | cpe:/a:redhat:openshift:3.11::el7 | RHBA-2019:2824 | 2019-09-24T00:00:00Z |
Red Hat OpenShift Container Platform 4.1 | |||
kibana-0:5.6.16-2.el7 | cpe:/a:redhat:openshift:4.1::el7 | RHSA-2019:2860 | 2019-09-30T00:00:00Z |
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: elastic
Published: 2019-03-25T18:34:06
Updated: 2024-08-04T20:54:28.309Z
Reserved: 2019-02-07T00:00:00
Link: CVE-2019-7610
Vulnrichment
No data.
NVD
Status : Modified
Published: 2019-03-25T19:29:02.197
Modified: 2024-11-21T04:48:23.807
Link: CVE-2019-7610
Redhat