S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Web Vulnerabilities·Updated Dec 16, 2023

CVE-2018-17246 Scanner

CVE-2018-17246 scanner - Local File Inclusion (LFI) vulnerability in Kibana

Est. Time~15 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
2.7k
Times Used
continuous scan runs
3.7k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2018-17246
9.8
CVSS

Kibana versions before 6.4.3 and 5.6.13 contain an arbitrary file inclusion flaw in the Console plugin. An attacker with access to the Kibana Console API could send a request that will attempt to execute javascript code. This could possibly lead to an attacker executing arbitrary commands with permissions of the Kibana process on the host system.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
Kibanaby Elastic
before 6.4.3 and 5.6.13
Updated Aug 18, 2026View on NVD →
Detail

Kibana is a powerful data visualization and exploration tool used to analyze large datasets. It is part of the Elastic Stack, which is a set of tools used to store, search, and analyze data. Kibana is commonly used by businesses, government agencies, and other organizations to monitor and understand their data. With Kibana, users can create custom dashboards, visualizations, and charts to make sense of their data.

However, Kibana versions prior to 6.4.3 and 5.6.13 contain a serious vulnerability, referred to as CVE-2018-17246. This arbitrary file inclusion flaw allows attackers with access to the Kibana Console API to execute javascript code. This can result in an attacker gaining the ability to execute arbitrary commands with the same permissions as the Kibana process on the host system.

When exploited, the CVE-2018-17246 vulnerability can lead to a wide range of security risks and threats. Potentially malicious actors can gain unauthorized access to sensitive data, compromise system resources, or even install malware on the host system. In such scenarios, organizations may incur significant financial losses, reputational damage, and loss of customer trust.

With the pro features of the s4e.io platform, businesses and organizations can stay ahead of the game when it comes to cybersecurity. By using the platform's advanced security monitoring and threat intelligence capabilities, users can quickly and easily detect and mitigate vulnerabilities in their digital assets. Thanks to s4e.io, organizations can rest assured that their data is safe from threats, no matter where it may be stored.

 

REFERENCES

Solution Advice

To mitigate the risks posed by this vulnerability, organizations can take certain precautions. A few of these include:

  • Upgrading to the latest version of Kibana
  • Restricting access to the Kibana Console API
  • Implementing firewall rules to limit external access to Kibana
  • Regularly auditing Kibana logs for suspicious activity
  • Investing in a robust cybersecurity solution that can detect and prevent attacks 

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.