Security Advisory

CVE-2024-37287

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2024-08-13 11:33:45
Last updated 2024-08-13 13:35:02
Assigner elastic
CVSS score 9.1
State PUBLISHED

Description

A flaw allowing arbitrary code execution was discovered in Kibana. An attacker with access to ML and Alerting connector features, as well as write access to internal ML indices can trigger a prototype pollution vulnerability, ultimately leading to arbitrary code execution.