CVE-2019-7616: SSRF
Kibana versions before 6.8.2 and 7.2.1 contain a server side request forgery (SSRF) flaw in the graphite integration for Timelion visualizer. An attacker with administrative Kibana access could set the timelion:graphite.url configuration option to an arbitrary URL. This could possibly lead to an attacker accessing external URL resources as the Kibana process on the host system.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this Kibana vulnerability?
The vulnerability ID for this Kibana vulnerability is CVE-2019-7616.
What is the severity rating of CVE-2019-7616?
CVE-2019-7616 has a severity rating of medium (4.9).
Which versions of Kibana are affected by CVE-2019-7616?
Kibana versions before 6.8.2 and 7.2.1 are affected by CVE-2019-7616.
What is the vulnerability described in CVE-2019-7616?
CVE-2019-7616 is a server side request forgery (SSRF) flaw in the graphite integration for Timelion visualizer in Kibana.
How can an attacker exploit CVE-2019-7616?
An attacker with administrative Kibana access could set the timelion:graphite.url configuration option to an arbitrary URL, potentially leading to an attack.