CVE-2018-17246
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
Kibana versions before 6.4.3 and 5.6.13 contain an arbitrary file inclusion flaw in the Console plugin. An attacker with access to the Kibana Console API could send a request that will attempt to execute javascript code. This could possibly lead to an attacker executing arbitrary commands with permissions of the Kibana process on the host system.
Kibana, en versiones anteriores a la 6.4.3 y la 5.6.13, contiene un error de inclusión de archivos arbitrarios en el plugin Console. Un atacante con acceso a la API de la consola de Kibana podría enviar una petición que intentará ejecutar código JavaScript. Esto podría conducir a que un atacante ejecute comandos arbitrarios con los permisos del proceso Kibana en el sistema host.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2018-09-20 CVE Reserved
- 2018-12-20 CVE Published
- 2019-10-26 First Exploit
- 2024-08-05 CVE Updated
- 2024-10-04 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-73: External Control of File Name or Path
- CWE-829: Inclusion of Functionality from Untrusted Control Sphere
CAPEC
References (5)
URL | Tag | Source |
---|---|---|
http://www.securityfocus.com/bid/106285 | Third Party Advisory |
URL | Date | SRC |
---|---|---|
https://github.com/mpgn/CVE-2018-17246 | 2019-10-26 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://access.redhat.com/errata/RHBA-2018:3743 | 2020-08-14 | |
https://discuss.elastic.co/t/elastic-stack-6-4-3-and-5-6-13-security-update/155594 | 2020-08-14 | |
https://www.elastic.co/community/security | 2020-08-14 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Elastic Search vendor "Elastic" | Kibana Search vendor "Elastic" for product "Kibana" | >= 5.0.0 < 5.6.13 Search vendor "Elastic" for product "Kibana" and version " >= 5.0.0 < 5.6.13" | - |
Affected
| ||||||
Elastic Search vendor "Elastic" | Kibana Search vendor "Elastic" for product "Kibana" | >= 6.0.0 < 6.4.3 Search vendor "Elastic" for product "Kibana" and version " >= 6.0.0 < 6.4.3" | - |
Affected
| ||||||
Redhat Search vendor "Redhat" | Openshift Container Platform Search vendor "Redhat" for product "Openshift Container Platform" | 3.11 Search vendor "Redhat" for product "Openshift Container Platform" and version "3.11" | - |
Affected
|