PT-2025-19890 · Kibana+1 · Kibana
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Kibana versions 8.3.0 through 8.17.5
Kibana version 8.18.0
Description
A prototype pollution flaw allows remote attackers to achieve arbitrary code execution. This occurs when the software fails to properly control the modification of object prototype attributes. The issue is triggered by sending specially crafted HTTP requests to the machine learning and reporting endpoints. Prototype pollution is a technique where an attacker manipulates the base prototype of an object to inject properties that can alter the behavior of the application.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
DoS
RCE
Prototype Pollution
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Kibana