CVE-2018-17246

Kibana versions before 6.4.3 and 5.6.13 contain an arbitrary file inclusion flaw in the Console plugin. An attacker with access to the Kibana Console API could send a request that will attempt to execute javascript code. This could possibly lead to an attacker executing arbitrary commands with permissions of the Kibana process on the host system.
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

OR cpe:2.3:a:elastic:kibana:*:*:*:*:*:*:*:*
cpe:2.3:a:elastic:kibana:*:*:*:*:*:*:*:*

Configuration 2 (hide)

cpe:2.3:a:redhat:openshift_container_platform:3.11:*:*:*:*:*:*:*

Information

Published : 2018-12-20 14:29

Updated : 2020-08-14 10:30


NVD link : CVE-2018-17246

Mitre link : CVE-2018-17246


JSON object : View

CWE
CWE-829

Inclusion of Functionality from Untrusted Control Sphere

Advertisement

dedicated server usa

Products Affected

elastic

  • kibana

redhat

  • openshift_container_platform