EXECUTIVE SUMMARY:
Researchers has identified a critical security vulnerability, tracked as CVE-2024-37287, with a CVSSv3 severity rating of 9.9, indicating a severe risk of arbitrary code execution. This flaw arises from a prototype pollution vulnerability that can be exploited by attackers with access to Machine Learning (ML) and Alerting connector features and write access to internal ML indices. Exploitation of this vulnerability can allow attackers to execute arbitrary code, posing significant security risks. The flaw affects multiple Kibana environments, including self-managed installations on host operating systems, Kibana Docker images, Elastic Cloud instances, Elastic Cloud Enterprise (ECE), and Kibana instances on Elastic Cloud on Kubernetes (ECK). In these environments, Remote Code Execution (RCE) is generally confined within the Kibana Docker container, with some additional protections provided by seccomp-bpf and AppArmor profiles, and Kubernetes support in ECK. Affected Kibana versions include 8.x versions earlier than 8.14.2 and 7.x versions earlier than 7.17.23. This situation underscores the critical need for timely software updates and rigorous security practices to protect against potential exploitation. Organizations using Kibana should prioritize these upgrades to ensure their systems remain secure against this critical threat.[/subscribe_to_unlock_form]
EXECUTIVE SUMMARY:
Researchers has identified a critical security vulnerability, tracked as CVE-2024-37287, with a CVSSv3 severity rating of 9.9, indicating a severe risk of arbitrary code execution. This flaw arises from a prototype pollution vulnerability that can be exploited by attackers with access to Machine Learning (ML) and Alerting connector features and write access to internal ML indices. Exploitation of this vulnerability can allow attackers to execute arbitrary code, posing significant security risks. The flaw affects multiple Kibana environments, including self-managed installations on host operating systems, Kibana Docker images, Elastic Cloud instances, Elastic Cloud Enterprise (ECE), and Kibana instances on Elastic Cloud on Kubernetes (ECK). In these environments, Remote Code Execution (RCE) is generally confined within the Kibana Docker container, with some additional protections provided by seccomp-bpf and AppArmor profiles, and Kubernetes support in ECK. Affected Kibana versions include 8.x versions earlier than 8.14.2 and 7.x versions earlier than 7.17.23. This situation underscores the critical need for timely software updates and rigorous security practices to protect against potential exploitation. Organizations using Kibana should prioritize these upgrades to ensure their systems remain secure against this critical threat.[emaillocker id="1283"]
RECOMMENDATION:
REFERENCES:
The following reports contain further technical details:
https://cybersecuritynews.com/critical-kibana-vulnerability/
[/emaillocker]