Kibana is an open-source visualisation plugin for Elasticsearch.The Timelion visualizer in Kibana versions prior to 5.6.15 and 6.6.1 has the ability to execute arbitrary code. An attacker with Timelion platform access may submit a request that attempts to execute javascript code. This may result in an attacker executing unauthorised commands on the host machine with the Kibana process’s permissions.
Vulnerability detection: