Skip to content
COOEY

EXPOSURES › CVE-2019-7609

CVE-2019-7609

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2022-01-10 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2019-7609 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 78/100 rceexploited-in-wildunpatchedransomware

Elastic Kibana's Timelion visualizer contained an arbitrary code execution flaw that was actively exploited in the wild.

The Kibana Timelion visualizer flaw allowed attackers to execute arbitrary code on systems running the software, enabling remote compromise of security operations and log analysis environments. DIB organizations must ensure Elastic products are patched against known CVEs, as unpatched vulnerabilities in widely deployed security tools can become critical entry points for adversaries. This failure highlights the risk of relying on software with known, unpatched vulnerabilities that are actively exploited in the wild.

Shame score — The vulnerability was actively exploited in the wild and linked to ransomware campaigns, demonstrating severe negligence in patching known, high-severity flaws in widely deployed security infrastructure.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Kibana contain an arbitrary code execution flaw in the Timelion visualizer.

AFFECTED FEDRAMP PRODUCTS · 1
PRODUCTSTATUS
Elastic Cloud
Elastic
Authorized