Sploitus

CVE-2019-7616

3 known exploits for CVE-2019-7616

Kibana versions before 6.8.2 and 7.2.1 contain a server side request forgery (SSRF) flaw in the graphite integration for Timelion visualizer. An attacker with administrative Kibana access could set the timelion:graphite.url configuration option to an arbitrary URL. This could possibly lead to an attacker accessing external URL resources as the Kibana process on the host system.

Affected products
Kibana
Elastic Kibana
< 6.8.2, 7.2.1
Fix
Available
CVSS 3.1
4.9 MEDIUM
EPSS
2.1% (80th percentile)
Weakness
CWE-918
NVD status
Modified
Published
2019-07-30
CVE-2019-7616 at NVD
Authoritative description, scoring and affected products

3 known exploits for CVE-2019-7616

Proof-of-concept code and exploit modules indexed by Sploitus