Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-54394 | Prototype Pollution in Kibana can lead to code injection via unrestricted file upload combined with path traversal. |
Thu, 02 Oct 2025 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:elastic:kibana:*:*:*:*:*:*:*:* |
Wed, 09 Apr 2025 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 08 Apr 2025 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Prototype Pollution in Kibana can lead to code injection via unrestricted file upload combined with path traversal. | |
| Title | Kibana Prototype Pollution can lead to code injection | |
| Weaknesses | CWE-1321 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: elastic
Published:
Updated: 2026-02-26T18:28:29.842Z
Reserved: 2024-12-11T22:26:54.970Z
Link: CVE-2024-12556
Updated: 2025-04-09T19:29:07.964Z
Status : Analyzed
Published: 2025-04-08T20:15:19.420
Modified: 2025-10-02T15:27:30.197
Link: CVE-2024-12556
No data.
OpenCVE Enrichment
Updated: 2025-07-13T11:31:02Z
EUVD