Prototype Pollution in Kibana can lead to code injection via unrestricted file upload combined with path traversal.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Thu, 02 Oct 2025 15:30:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:elastic:kibana:*:*:*:*:*:*:*:*

Wed, 09 Apr 2025 20:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 08 Apr 2025 20:15:00 +0000

Type Values Removed Values Added
Description Prototype Pollution in Kibana can lead to code injection via unrestricted file upload combined with path traversal.
Title Kibana Prototype Pollution can lead to code injection
Weaknesses CWE-1321
References
Metrics cvssV3_1

{'score': 8.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: elastic

Published:

Updated: 2025-04-10T03:55:27.663Z

Reserved: 2024-12-11T22:26:54.970Z

Link: CVE-2024-12556

cve-icon Vulnrichment

Updated: 2025-04-09T19:29:07.964Z

cve-icon NVD

Status : Analyzed

Published: 2025-04-08T20:15:19.420

Modified: 2025-10-02T15:27:30.197

Link: CVE-2024-12556

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2025-07-13T11:31:02Z