SB2024080624 - Prototype pollution in Kibana



SB2024080624 - Prototype pollution in Kibana

Published: August 6, 2024

Security Bulletin ID SB2024080624
Severity
High
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Code execution

Breakdown by Severity

High 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Prototype pollution (CVE-ID: CVE-2024-37287)

The vulnerability allows a remote user to execute arbitrary JavaScript code.

The vulnerability exists due to improper input validation. A remote user with access to ML and Alerting connector features, as well as write access to internal ML indices, can pass specially crafted input to the application and perform prototype pollution, which can result code execution.


Remediation

Install update from vendor's website.