CVE-2024-12556

Prototype Pollution in Kibana can lead to code injection via unrestricted file upload combined with path traversal.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:elastic:kibana:*:*:*:*:*:*:*:*
cpe:2.3:a:elastic:kibana:*:*:*:*:*:*:*:*

History

02 Oct 2025, 15:27

Type Values Removed Values Added
First Time Elastic kibana
Elastic
CPE cpe:2.3:a:elastic:kibana:*:*:*:*:*:*:*:*
References () https://discuss.elastic.co/t/kibana-8-16-4-and-8-17-2-security-update-esa-2025-02/376918 - () https://discuss.elastic.co/t/kibana-8-16-4-and-8-17-2-security-update-esa-2025-02/376918 - Patch, Vendor Advisory

09 Apr 2025, 20:02

Type Values Removed Values Added
Summary
  • (es) La contaminación de prototipos en Kibana puede provocar la inyección de código a través de la carga de archivos sin restricciones combinada con el path traversal.

08 Apr 2025, 20:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-04-08 20:15

Updated : 2025-10-02 15:27


NVD link : CVE-2024-12556

Mitre link : CVE-2024-12556

CVE.ORG link : CVE-2024-12556


JSON object : View

Products Affected

elastic

  • kibana
CWE
CWE-1321

Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')