Cross-site Request Forgery (CSRF) Affecting kibana package, versions *


Severity

Recommended
0.0
low
0
10

Based on Red Hat Enterprise Linux security rating.

Threat Intelligence

EPSS
0.07% (31st percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications

Snyk Learn

Learn about Cross-site Request Forgery (CSRF) vulnerabilities in an interactive lesson.

Start learning
  • Snyk IDSNYK-RHEL9-KIBANA-3389849
  • published26 Mar 2023
  • disclosed31 Jul 2019

Introduced: 31 Jul 2019

CVE-2019-7616  (opens in a new tab)
CWE-352  (opens in a new tab)

How to fix?

There is no fixed version for RHEL:9 kibana.

NVD Description

Note: Versions mentioned in the description apply only to the upstream kibana package and not the kibana package as distributed by RHEL. See How to fix? for RHEL:9 relevant fixed versions and status.

Kibana versions before 6.8.2 and 7.2.1 contain a server side request forgery (SSRF) flaw in the graphite integration for Timelion visualizer. An attacker with administrative Kibana access could set the timelion:graphite.url configuration option to an arbitrary URL. This could possibly lead to an attacker accessing external URL resources as the Kibana process on the host system.

CVSS Scores

version 3.1