Web Hack List

Collected research

Exploiting prototype pollution - RCE in Kibana

Exploiting prototype pollution - RCE in Kibana (CVE-2019-7609)

Turns prototype pollution into remote code execution in Kibana. A Timelion expression that assigns through an object's prototype pollutes Object.prototype, and Kibana's Canvas then spawns a node child process whose environment the attacker now controls, setting NODE_OPTIONS to require /proc/self/environ so another injected variable runs as JavaScript.

Record

Document
Exploiting prototype pollution - RCE in Kibana (CVE-2019-7609)
Researcher
@SecurityMB
Published by
research.securitum.com
Date
Topic
Injection

In the archive

Related sources

Tags

This page is the archive's own catalogue record. The research is the work of @SecurityMB, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .