Kibana versions before 5.6.15 and 6.6.1 contain an arbitrary code execution flaw in the Timelion visualizer https://nvd.nist.gov/vuln/detail/CVE-2019-7609
该漏洞是 Kibana 中发现的 Prototype Pollution 漏洞。利用此漏洞可能导致 DoS 或 RCE 攻击。
进行安装时,请在 docker-compose.yml 文件中进行端口转发。
$ docker-compose up
https://github.com/hekadan/CVE-2019-7609
https://www.cnblogs.com/anyun/p/8458476.html
https://slides.com/securitymb/prototype-pollution-in-kibana/#/41