Deserialization Flaw in Kibana by Elastic Search
CVE-2024-37285
Currently unrated
Key Information:
Badges
๐พ Exploit Exists๐ฐ News Worthy
Summary
A deserialization issue in Kibana allows attackers to execute arbitrary code by manipulating YAML documents. This vulnerability arises when Kibana incorrectly processes crafted payloads, necessitating specific permissions on Elasticsearch indices and within Kibana. Attackers must possess both write privilege on system indices .kibana_ingest* and the ability to manipulate restricted indices, combined with comprehensive Kibana privileges. Such an exploit poses significant risks to systems utilizing Kibana for visualization and data analysis.
Get notified when SecurityVulnerability.io launches alerting ๐
Well keep you posted ๐ง
News Articles
References
Timeline
Vulnerability published
- ๐พ
Exploit known to exist
- ๐ฐ
First article discovered by CybersecurityNews