CVE-2024-37287: Kibana arbitrary code execution via prototype pollution
A flaw allowing arbitrary code execution was discovered in Kibana. An attacker with access to ML and Alerting connector features, as well as write access to internal ML indices can trigger a prototype pollution vulnerability, ultimately leading to arbitrary code execution.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-37287?
CVE-2024-37287 is classified as a critical vulnerability due to the potential for arbitrary code execution.
How do I fix CVE-2024-37287?
To fix CVE-2024-37287, upgrade Kibana to version 8.14.3 or later, or version 7.17.24 or later.
What types of attacks can CVE-2024-37287 enable?
CVE-2024-37287 can enable arbitrary code execution attacks if exploited by an attacker with access to specific features.
Which versions of Kibana are affected by CVE-2024-37287?
CVE-2024-37287 affects Kibana versions between 7.7.0 and 7.17.23, and between 8.0.0 and 8.14.2.
What should I do if I can't immediately upgrade to fix CVE-2024-37287?
If unable to upgrade immediately for CVE-2024-37287, restrict access to ML and Alerting connector features to mitigate the risk.