資料圖像化系統Kibana存在重大漏洞,可被用於執行任意程式碼
支付動態 · 2024-09-10

近期Elastic發布資料圖像化系統Kibana安全性更新8.15.1版,值得留意的是,本次修補的漏洞都相當嚴重,他們呼籲IT人員儘速套用新版程式因應

資料搜尋和分析解決方案業者Elastic推出資料圖像化系統Kibana安全性更新8.15.1版,修補2項重大層級的漏洞CVE-2024-37288、CVE-2024-37285。

根據CVSS風險評分,較為危險的是CVE-2024-37288,這項漏洞發生的原因,在於Kibana的Amazon Bedrock Connector元件當中,存在去序列化(deserialization)的弱點,當Kibana嘗試處理含有惡意酬載的YAML檔案,就有可能觸發,使得攻擊者能夠執行任意程式碼,CVSS風險評為9.9分(滿分為10分),影響8.15.0版Kibana。

另一個漏洞CVE-2024-37285也與去序列化有關,攻擊者同樣可藉由特製的YAML檔案觸發,並執行任意程式碼,但利用這項漏洞,攻擊者必須事先得到具備指定權限的惡意使用者帳號,並結合特定的Elasticsearch、Kibana權限,此漏洞的CVSS風險評分為9.1,影響8.10.0至8.15.0版Kibana。

Popular articles
GAT CDMX 2025 Institutional Academy: Leaders and Experts Analyze the Present and Future of the Gaming Industry in Mexico and Lat
Sports Game
UK MPs reopen 2025 gambling inquiry as reform stalls
Regulation
SBC Summit Canada to Make Player Safety a Key Pillar of 2026 Agenda
Marketing
Vietnam’s Controlled Gaming Shift Gains Ground, But Domestic Demand Still Lags
Southeast Asia
GGC Awards 2026 Shines in Colombo: Honoring Leaders and Innovators in the iGaming Industry
HUIDU Focus
GAT Expo Puerto Rico Will Pulse with the New Era of Gaming in the Caribbean
Marketing
Indiana online casino bill stalls in House committee
Regulation
Super PAC Raises $48 Million: Sports Betting Forces Ramp Up Political Push
Regulation
Brazil Proposes Raising Gambling Tax Rate to 24%, With Revenue Allocated to Social Security and Healthcare
Regulation
HUIDU Invites You to Booth T70 at iGB L!VE 2026 — Let’s Ignite London This July!
HUIDU Focus
Across 6 Cities: HUIDU Invites You to 8 World Cup Parties Redefining High-Value Social Networking
HUIDU Focus
Institutional Academy that exceeded expectations marked the opening of GAT CDMX
Online Game
Full House at GAT Expo Cartagena 2026 Academic Agenda
Online Game
Are you ready to maximize your earnings? Try ProPush.me Constructor!
Marketing
PropellerAds Shared a New iGaming Case Study: 97,674 Installs and 12,701 Deposits in 3 Months
Marketing
Home
Game
Cooperation
Find
My