Sploitus

CVE-2024-37287

No indexed exploits for CVE-2024-37287 yet

A flaw allowing arbitrary code execution was discovered in Kibana. An attacker with access to ML and Alerting connector features, as well as write access to internal ML indices can trigger a prototype pollution vulnerability, ultimately leading to arbitrary code execution.

Affected products
Kibana
Elastic Kibana
< 7.17.23, 8.14.2
Fix
Available
CVSS 3.1
9.1 CRITICAL
EPSS
1.6% (74th percentile)
Weakness
CWE-1321, CWE-94
NVD status
Analyzed
Published
2024-08-13
Attack patterns
CAPEC-242
CVE-2024-37287 at NVD
Authoritative description, scoring and affected products

No indexed exploits for CVE-2024-37287 yet

Our index is partial: it proves presence, never absence

No exploit for CVE-2024-37287 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.