SB2024080624 - Prototype pollution in Kibana
Published: August 6, 2024
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Prototype pollution (CVE-ID: CVE-2024-37287)
The vulnerability allows a remote user to execute arbitrary JavaScript code.
The vulnerability exists due to improper input validation. A remote user with access to ML and Alerting connector features, as well as write access to internal ML indices, can pass specially crafted input to the application and perform prototype pollution, which can result code execution.
Remediation
Install update from vendor's website.