S4E just found a high top 10 tcp port service scan
critical·Product Based Web Vulnerabilities·Updated Dec 16, 2023

CVE-2019-7609 Scanner

CVE-2019-7609 scanner - Code Injection vulnerability in Kibana

Est. Time~15 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
0
Times Used
by S4E users
0
Assets Scanned
domains & IPs
0
Vulnerabilities Found
confirmed findings
References
🔴
CISA Known Exploited Vulnerability
This CVE is actively exploited in the wild. CISA mandates federal agencies to patch immediately.
CVECVE-2019-7609
10.0
CVSScritical
Exploitable remotely over the internet · no authentication required.

Kibana versions before 5.6.15 and 6.6.1 contain an arbitrary code execution flaw in the Timelion visualizer. An attacker with access to the Timelion application could send a request that will attempt to execute javascript code. This could possibly lead to an attacker executing arbitrary commands with permissions of the Kibana process on the host system.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
Kibanaby Elastic
before 5.6.15 and 6.6.1
Updated Aug 21, 2026View on NVD →
Detail

Kibana is an open-source data visualization and exploration platform used to analyze data stored within Elasticsearch. It provides interactive dashboards, advanced visualization techniques and powerful search capabilities which make it a popular choice among data analysts and developers. It is available as a web-based service and allows users to create and share customized dashboards with others in the same organization.

However, Kibana versions before 5.6.15 and 6.6.1 contain a critical vulnerability, CVE-2019-7609, that could allow an attacker to execute arbitrary commands on the host system by sending a request to the Timelion visualizer. The vulnerability stems from a lack of input validation, which would enable an attacker with access to the Timelion application to execute JavaScript code. This, in turn, could give the attacker unauthorized access to the Kibana host system and all the data that resides on it.

When exploited, this vulnerability could lead to a variety of potential security threats. An attacker could gain full control over the Kibana host system, granting them access to confidential data that was being analyzed within Kibana. Attackers could also use this vulnerability to launch further attacks against the host system or other devices connected to the network. Furthermore, if the Kibana host system is connected to other systems such as databases or API systems, the attacker could potentially compromise those systems as well.

Thanks to the pro features of the s4e.io platform, those who read this article can easily and quickly learn about vulnerabilities in their digital assets. The platform provides real-time threat detection, continuous vulnerability assessment, and an easy-to-use dashboard, allowing users to identify and remediate security risks before any damage can be done. With its comprehensive set of cybersecurity tools, s4e.io is an essential resource for organizations and individuals who want to stay on top of the latest threats and vulnerabilities.

 

REFERENCES

Solution Advice

To protect against this vulnerability, several precautions can be taken, including:

  • Updating to the latest version of Kibana
  • Disabling the Timelion plugin if it's not being used
  • Limiting access to the Timelion application through role-based access control
  • Implementing network segmentation to limit an attacker's access to the Kibana host system
  • Monitoring system logs for any suspicious activity

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2019-7609 scanner - Code Injection vulnerability in Kibana S4E