First published: Tue Apr 08 2025(Updated: )
Prototype Pollution in Kibana can lead to code injection via unrestricted file upload combined with path traversal.
Credit: bressers@elastic.co
Affected Software | Affected Version | How to fix |
---|---|---|
Elastic |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-12556 has a high severity rating due to its potential for code injection and prototype pollution.
To mitigate CVE-2024-12556, ensure you are using the latest version of Kibana and implement proper file upload validation.
CVE-2024-12556 affects multiple versions of Kibana prior to the latest security patches.
Exploitation of CVE-2024-12556 can lead to unauthorized code execution through unvalidated file uploads.
Implementing strict input validation and file handling can serve as a temporary workaround for CVE-2024-12556.