Organizations using Kibana should review their security posture, ensure proper access controls are in place, and implement the recommended mitigations to protect against this and other potential vulnerabilities in their data visualization infrastructure. The security update patches a prototype pollution vulnerability that, when exploited, could lead to remote code execution through a sophisticated attack chain. Security researchers discovered that attackers could exploit a prototype pollution weakness combined with unrestricted file upload and path traversal techniques to achieve code injection. Cyber Security News is a Dedicated News Platform For Cyber News, Cyber Attack News, Hacking News & Vulnerability Analysis. The Elastic documentation specifically notes that rolling upgrades are unsupported in Kibana, meaning all instances must be shut down before upgrading to prevent data loss or upgrade failures. These vulnerabilities highlight the importance of promptly applying security updates to data visualization and analytics platforms, especially those handling sensitive organizational data. Kaaviya is a Security Editor and fellow reporter with Cyber Security News. She is covering various cyber security incidents happening in the Cyber Space.
This Cyber News was published on cybersecuritynews.com. Publication date: Wed, 09 Apr 2025 08:30:25 +0000