Collected research
Exploiting the Unexploitable Insights from the Kibana Bug Bounty
Kibana's synthetic-monitoring feature runs user-pasted JavaScript by design, and NET_RAW on the container turned that into ARP spoofing of the cluster. CodeQL then found server-side prototype pollution in the kibana.yml parser, whose dotted-key expansion writes through __proto__, and in a DELETE uptime handler. Pollution crashes Kibana within a second, so the gadgets - require()'s package.json fields, nodemailer's sendmail path - are reached by flooding requests around the polluting one.
Record
- Researcher
- Mikhail Shcherbakov
- Published by
- media.defcon.org
- Format
- Whitepaper
- Topic
- Other
In the archive
Related sources
Tags
This page is the archive's own catalogue record. The research is the work of Mikhail Shcherbakov, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .