CVE-2019-7618 Vulnerability Details

  /     /     /  

CVE-2019-7618 Metadata Quick Info

CVE Published: 01/10/2019 | CVE Updated: 04/08/2024 | CVE Year: 2019
Source: elastic | Vendor: Elastic | Product: Elastic Code
Status : PUBLISHED

CVE-2019-7618 Description

A local file disclosure flaw was found in Elastic Code versions 7.3.0, 7.3.1, and 7.3.2. If a malicious code repository is imported into Code it is possible to read arbitrary files from the local filesystem of the Kibana instance running Code with the permission of the Kibana system user.

Metrics

CVSS Version: 3.1 | Base Score: n/a
Vector: n/a

l➤ Exploitability Metrics:
    Attack Vector (AV)*
    Attack Complexity (AC)*
    Privileges Required (PR)*
    User Interaction (UI)*
    Scope (S)*

l➤ Impact Metrics:
    Confidentiality Impact (C)*
    Integrity Impact (I)*
    Availability Impact (A)*

Weakness Enumeration (CWE)

CWE-ID: CWE-538
CWE Name: CWE-538: File and Directory Information Exposure
Source: Elastic

Common Attack Pattern Enumeration and Classification (CAPEC)

CAPEC-ID:
CAPEC Description:


Source: NVD (National Vulnerability Database).