Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2018-17246

Kibana versions before 6.4.3 and 5.6.13 contain an arbitrary file inclusion flaw in the Console plugin. An attacker with access to the Kibana Console API could send a request that will attempt to execute javascript code. This could possibly lead to an attacker executing arbitrary commands with permissions of the Kibana process on the host system.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.939
EPSS Ranking 99.9%
CVSS Severity
CVSS v3 Score 9.8
CVSS v2 Score 7.5
Products affected by CVE-2018-17246
  • Elastic » Kibana » Version: 5.0.0
    cpe:2.3:a:elastic:kibana:5.0.0
  • Elastic » Kibana » Version: 5.0.1
    cpe:2.3:a:elastic:kibana:5.0.1
  • Elastic » Kibana » Version: 5.0.2
    cpe:2.3:a:elastic:kibana:5.0.2
  • Elastic » Kibana » Version: 5.1.1
    cpe:2.3:a:elastic:kibana:5.1.1
  • Elastic » Kibana » Version: 5.1.2
    cpe:2.3:a:elastic:kibana:5.1.2
  • Elastic » Kibana » Version: 5.2.0
    cpe:2.3:a:elastic:kibana:5.2.0
  • Elastic » Kibana » Version: 5.2.1
    cpe:2.3:a:elastic:kibana:5.2.1
  • Elastic » Kibana » Version: 5.2.2
    cpe:2.3:a:elastic:kibana:5.2.2
  • Elastic » Kibana » Version: 5.3.0
    cpe:2.3:a:elastic:kibana:5.3.0
  • Elastic » Kibana » Version: 5.3.1
    cpe:2.3:a:elastic:kibana:5.3.1
  • Elastic » Kibana » Version: 5.3.2
    cpe:2.3:a:elastic:kibana:5.3.2
  • Elastic » Kibana » Version: 5.3.3
    cpe:2.3:a:elastic:kibana:5.3.3
  • Elastic » Kibana » Version: 5.4.0
    cpe:2.3:a:elastic:kibana:5.4.0
  • Elastic » Kibana » Version: 5.4.1
    cpe:2.3:a:elastic:kibana:5.4.1
  • Elastic » Kibana » Version: 5.4.2
    cpe:2.3:a:elastic:kibana:5.4.2
  • Elastic » Kibana » Version: 5.4.3
    cpe:2.3:a:elastic:kibana:5.4.3
  • Elastic » Kibana » Version: 5.5.0
    cpe:2.3:a:elastic:kibana:5.5.0
  • Elastic » Kibana » Version: 5.5.1
    cpe:2.3:a:elastic:kibana:5.5.1
  • Elastic » Kibana » Version: 5.5.2
    cpe:2.3:a:elastic:kibana:5.5.2
  • Elastic » Kibana » Version: 5.5.3
    cpe:2.3:a:elastic:kibana:5.5.3
  • Elastic » Kibana » Version: 5.6.0
    cpe:2.3:a:elastic:kibana:5.6.0
  • Elastic » Kibana » Version: 5.6.1
    cpe:2.3:a:elastic:kibana:5.6.1
  • Elastic » Kibana » Version: 5.6.10
    cpe:2.3:a:elastic:kibana:5.6.10
  • Elastic » Kibana » Version: 5.6.11
    cpe:2.3:a:elastic:kibana:5.6.11
  • Elastic » Kibana » Version: 5.6.12
    cpe:2.3:a:elastic:kibana:5.6.12
  • Elastic » Kibana » Version: 5.6.2
    cpe:2.3:a:elastic:kibana:5.6.2
  • Elastic » Kibana » Version: 5.6.3
    cpe:2.3:a:elastic:kibana:5.6.3
  • Elastic » Kibana » Version: 5.6.4
    cpe:2.3:a:elastic:kibana:5.6.4
  • Elastic » Kibana » Version: 5.6.5
    cpe:2.3:a:elastic:kibana:5.6.5
  • Elastic » Kibana » Version: 5.6.6
    cpe:2.3:a:elastic:kibana:5.6.6
  • Elastic » Kibana » Version: 5.6.7
    cpe:2.3:a:elastic:kibana:5.6.7
  • Elastic » Kibana » Version: 5.6.8
    cpe:2.3:a:elastic:kibana:5.6.8
  • Elastic » Kibana » Version: 5.6.9
    cpe:2.3:a:elastic:kibana:5.6.9
  • Elastic » Kibana » Version: 6.0.0
    cpe:2.3:a:elastic:kibana:6.0.0
  • Elastic » Kibana » Version: 6.0.1
    cpe:2.3:a:elastic:kibana:6.0.1
  • Elastic » Kibana » Version: 6.1.0
    cpe:2.3:a:elastic:kibana:6.1.0
  • Elastic » Kibana » Version: 6.1.1
    cpe:2.3:a:elastic:kibana:6.1.1
  • Elastic » Kibana » Version: 6.1.2
    cpe:2.3:a:elastic:kibana:6.1.2
  • Elastic » Kibana » Version: 6.1.3
    cpe:2.3:a:elastic:kibana:6.1.3
  • Elastic » Kibana » Version: 6.1.4
    cpe:2.3:a:elastic:kibana:6.1.4
  • Elastic » Kibana » Version: 6.2.0
    cpe:2.3:a:elastic:kibana:6.2.0
  • Elastic » Kibana » Version: 6.2.1
    cpe:2.3:a:elastic:kibana:6.2.1
  • Elastic » Kibana » Version: 6.2.2
    cpe:2.3:a:elastic:kibana:6.2.2
  • Elastic » Kibana » Version: 6.2.3
    cpe:2.3:a:elastic:kibana:6.2.3
  • Elastic » Kibana » Version: 6.2.4
    cpe:2.3:a:elastic:kibana:6.2.4
  • Elastic » Kibana » Version: 6.3.0
    cpe:2.3:a:elastic:kibana:6.3.0
  • Elastic » Kibana » Version: 6.3.1
    cpe:2.3:a:elastic:kibana:6.3.1
  • Elastic » Kibana » Version: 6.3.2
    cpe:2.3:a:elastic:kibana:6.3.2
  • Elastic » Kibana » Version: 6.4.0
    cpe:2.3:a:elastic:kibana:6.4.0
  • Elastic » Kibana » Version: 6.4.1
    cpe:2.3:a:elastic:kibana:6.4.1
  • Elastic » Kibana » Version: 6.4.2
    cpe:2.3:a:elastic:kibana:6.4.2
  • Redhat » Openshift Container Platform » Version: 3.11
    cpe:2.3:a:redhat:openshift_container_platform:3.11


Contact Us

Shodan ® - All rights reserved