RULE(RULE ID:338749)

Rule General Information
Release Date: 2025-03-19
Rule Name: Kibana 7.6.2 upgrade-assistant-telemetry Code Injection Vulnerability (CVE-2020-7012)
Severity:
CVE ID:
Rule Protection Details
Description: Elasticsearch Kibana is an open-source, browser based analysis and search dashboard tool developed by the Dutch company Elasticsearch. There is a code injection vulnerability in Upgrade Assistant>in Elasticsearch Kibana versions 6.7.0 to 6.8.8 and 7.0.0 to 7.6.2. Attackers can exploit this vulnerability to execute code within the context of the Kibana process.
Impact: An attacker could exploit this vulnerability to have unspecified effect.
Affected OS: Windows, Linux, Others
Reference:
Solutions
Please contact the software vendor to update the software patch.