Kibana versions before 5.6.15 and 6.6.1 contain an arbitrary code execution flaw in the Timelion visualizer. An attacker with access to the Timelion application could send a request that will attempt to execute javascript code. This could possibly lead to an attacker executing arbitrary commands with permissions of the Kibana process on the host system.
2019-03-25T19:29:02.147
2025-10-22T00:16:48.783
Modified
CVSSv3.1: 10.0 (CRITICAL)
AV:N/AC:L/Au:N/C:C/I:C/A:C
10.0
10.0
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Application | elastic | kibana | < 5.6.15 | Yes |
| Application | elastic | kibana | < 6.6.1 | Yes |
| Application | redhat | openshift_container_platform | 3.11 | Yes |
| Application | redhat | openshift_container_platform | 4.1 | Yes |