CVE-2020-7013: Code Injection
Kibana versions before 6.8.9 and 7.7.0 contain a prototype pollution flaw in TSVB. An authenticated attacker with privileges to create TSVB visualizations could insert data that would cause Kibana to execute arbitrary code. This could possibly lead to an attacker executing code with the permissions of the Kibana process on the host system.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-7013?
CVE-2020-7013 is a vulnerability in Kibana versions before 6.8.9 and 7.7.0 that allows authenticated attackers with privileges to create TSVB visualizations to execute arbitrary code.
What is the severity of CVE-2020-7013?
CVE-2020-7013 has a severity rating of 7.2 (High).
How can I fix CVE-2020-7013?
To fix CVE-2020-7013, you need to upgrade Kibana to version 6.8.9 or 7.7.0.
Where can I find more information about CVE-2020-7013?
You can find more information about CVE-2020-7013 on the CVE website, NIST NVD, Elastic forums, and Red Hat Bugzilla.
What is the Common Weakness Enumeration (CWE) of CVE-2020-7013?
The Common Weakness Enumeration (CWE) of CVE-2020-7013 is CWE-94 (Improper Control of Generation of Code ('Code Injection')).