EXPOSURES › CVE-2019-7609
CVE-2019-7609
HIGH ⌖ ON CISA KEV · EXPLOITEDElastic Kibana's Timelion visualizer contained an arbitrary code execution flaw that was actively exploited in the wild.
The Kibana Timelion visualizer flaw allowed attackers to execute arbitrary code on systems running the software, enabling remote compromise of security operations and log analysis environments. DIB organizations must ensure Elastic products are patched against known CVEs, as unpatched vulnerabilities in widely deployed security tools can become critical entry points for adversaries. This failure highlights the risk of relying on software with known, unpatched vulnerabilities that are actively exploited in the wild.
Shame score — The vulnerability was actively exploited in the wild and linked to ransomware campaigns, demonstrating severe negligence in patching known, high-severity flaws in widely deployed security infrastructure.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Kibana contain an arbitrary code execution flaw in the Timelion visualizer.
| PRODUCT | STATUS |
|---|---|
| Elastic Cloud Elastic |
Authorized |