Prototype Pollution in Kibana can lead to code injection via unrestricted file upload combined with path traversal.
2025-04-08T20:15:19.420
2025-10-02T15:27:30.197
Analyzed
CVSSv3.1: 8.7 (HIGH)
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Application | elastic | kibana | < 8.16.4 | Yes |
| Application | elastic | kibana | < 8.17.2 | Yes |