## https://sploitus.com/exploit?id=DCFE3B87-DB52-53A3-8ED6-D8E4E7F8310E
# CVE-2019-7609
Kibana versions before 5.6.15 and 6.6.1 contain an arbitrary code execution flaw in the Timelion visualizer
https://nvd.nist.gov/vuln/detail/CVE-2019-7609
# CVE-2019-7609
์ ์ทจ์ฝ์ ์ Kibana์์ ๋ฐ๊ฒฌ๋ Prototype Pollution ์ทจ์ฝ์ ์
๋๋ค. ์ด ์ทจ์ฝ์ ์ ์
์ฉํ๋ฉด DoS๋ RCE ๊ณต๊ฒฉ์ผ๋ก ์ด์ด์ง ์ ์์ต๋๋ค.
# ํน์ง
* Node์์ ์ ๊ณตํ๊ณ ์๋ debugging ์ต์
์ ์ถ๊ฐํ์์ต๋๋ค.
* Chrome://inspect๋ก ๋ค์ด๊ฐ ๋๋ฒ๊น
์ ์ด์ฉํ ์ ์์ต๋๋ค.
# ์ค์น ๋ฐ ์คํ ์์
#### 1. Kibana ์ค์น
์ค์น๋ฅผ ์งํํ ๋, docker-compose.yml ํ์ผ์์ ํฌํธํฌ์๋ฉ์ ์งํํด์ฃผ์๊ธฐ ๋ฐ๋๋๋ค.
$ docker-compose up
#### 2. ๋๋ฒ๊น
์ฐ๊ฒฐ
# ์ถ์ฒ
https://github.com/hekadan/CVE-2019-7609
https://www.cnblogs.com/anyun/p/8458476.html
https://slides.com/securitymb/prototype-pollution-in-kibana/#/41
# ์ฃผ์ ์ฌํญ
#### ์ ์ทจ์ฝ์ ์ ๋ถ๋ฒ์ผ๋ก ์
์ฉํ ์, ๋ฒ์ ์ฑ
์์ ์ง์ง ์์ต๋๋ค.
#### If you illegally exploit the above vulnerabilities, you will not be held liable.
#### docker ๋ฒ์ ์ ์ต์ ํ ํด์ผ ํฉ๋๋ค.