Kibana 6.5.4 with Elasticsearch 6.8.6, vulnerable to CVE-2019-7609: a Timelion expression sets __proto__ properties, and when Kibana next spawns a Node child process (opening Canvas) the polluted env runs a command.
Pas commencéDockercommit 7de9fffx86_64 · aarch64Secret
Exploit CVE-2019-7609 to run commands on the Kibana server and get a shell.
Le brief de ce lab se trouve dans son dépôt.