[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

250363

 
 

909

 
 

196124

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

Prototype pollution vulnerability in Kibana - CVE-2020-7012 (MacOS)

ID: oval:org.secpod.oval:def:67623Date: (C)2020-12-04   (M)2021-06-02
Class: VULNERABILITYFamily: macos




The host is installed with Kibana before 6.8.9 or 7.x before 7.7.0 and is prone to a prototype pollution vulnerability. A flaw is present in the application, which fails to properly handle an issue in Upgrade Assistant. Successful exploitation could allow an authenticated attacker to insert data that would cause Kibana to execute arbitrary code.

Platform:
Apple Mac OS 11
Apple Mac OS X 10.11
Apple Mac OS X 10.12
Apple Mac OS X 10.13
Apple Mac OS X 10.14
Apple Mac OS X 10.15
Product:
Kibana
Reference:
CVE-2020-7012
CVE    1
CVE-2020-7012
CPE    1
cpe:/a:elasticsearch:kibana

© SecPod Technologies