CVE Vulnerabilities

CVE-2019-7618

Insertion of Sensitive Information into Externally-Accessible File or Directory

Published: Oct 01, 2019 | Modified: Nov 21, 2024
CVSS 3.x
6.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
3.5 LOW
AV:N/AC:M/Au:S/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu

A local file disclosure flaw was found in Elastic Code versions 7.3.0, 7.3.1, and 7.3.2. If a malicious code repository is imported into Code it is possible to read arbitrary files from the local filesystem of the Kibana instance running Code with the permission of the Kibana system user.

Weakness

The product places sensitive information into files or directories that are accessible to actors who are allowed to have access to the files, but not to the sensitive information.

Affected Software

Name Vendor Start Version End Version
Kibana Elastic 7.3.0 (including) 7.3.0 (including)
Kibana Elastic 7.3.1 (including) 7.3.1 (including)
Kibana Elastic 7.3.2 (including) 7.3.2 (including)

Potential Mitigations

References