Other nomination
Exploiting prototype pollution - RCE in Kibana
Turns prototype pollution into remote code execution in Kibana. A Timelion expression that assigns through an object's prototype pollutes Object.prototype, and Kibana's Canvas then spawns a node child process whose environment the attacker now controls, setting NODE_OPTIONS to require /proc/self/environ so another injected variable runs as JavaScript.
Record
- Researcher
- @SecurityMB
- Date
In the archive
Related sources
Tags
This page is the archive's own catalogue record. The research is the work of @SecurityMB, first published at the original source. Preserved copies are kept so the citation survives its host.