CVE Database
/

CVE-2019-7616

Back to search

CVE-2019-7616

Published: Jul 30, 2019

Modified: Aug 4, 2024

PUBLISHED

Description

Kibana versions before 6.8.2 and 7.2.1 contain a server side request forgery (SSRF) flaw in the graphite integration for Timelion visualizer. An attacker with administrative Kibana access could set the timelion:graphite.url configuration option to an arbitrary URL. This could possibly lead to an attacker accessing external URL resources as the Kibana process on the host system.

VendorProductVersions

Elastic

Kibana

affected
before 7.2.1 and 6.8.2

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now