HIGH

CVE-2020-7012

CVSS v3

8.8

HIGH

EPSS Score

73.4%

exploit probability

CISA KEV

No

known exploited

Exploitation

SSVC status

Description

Kibana versions 6.7.0 to 6.8.8 and 7.0.0 to 7.6.2 contain a prototype pollution flaw in the Upgrade Assistant. An authenticated attacker with privileges to write to the Kibana index could insert data that would cause Kibana to execute arbitrary code. This could possibly lead to an attacker executing code with the permissions of the Kibana process on the host system.

Technical details

Published
6/3/2020

Frequently asked questions

What is CVE-2020-7012?

Kibana versions 6.7.0 to 6.8.8 and 7.0.0 to 7.6.2 contain a prototype pollution flaw in the Upgrade Assistant. An authenticated attacker with privileges to write to the Kibana index could insert data that would cause Kibana to execute arbitrary code. This could possibly lead to an attacker executing code with the permissions of the Kibana process on the host system.

Is CVE-2020-7012 actively exploited?

Active exploitation of CVE-2020-7012 has not been confirmed. The EPSS score is 73.4%, indicating the estimated probability of exploitation in the next 30 days.

What is the CVSS score for CVE-2020-7012?

CVE-2020-7012 has a CVSS v3 base score of 8.8 (HIGH severity).

Is CVE-2020-7012 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.