CVE-2024-37285
A deserialization issue in Kibana can lead to arbitrary code execution when Kibana attempts to parse a YAML document containing a crafted payload. A successful attack requires a malicious user to have a combination of both specific Elasticsearch indices privileges https://www.elastic.co/guide/en/elasticsearch/reference/current/defining-roles.html#roles-indices-priv and Kibana privileges https://www.elastic.co/guide/en/fleet/current/fleet-roles-and-privileges.html assigned to them.
The following Elasticsearch indices permissions are required
Any of the following Kibana privileges are additionally required
Technical details traces, logs and code from the original report
* write privilege on the system indices .kibana_ingest* * The allow_restricted_indices flag is set to true * Under Fleet the All privilege is granted * Under Integration the Read or All privilege is granted * Access to the fleet-setup privilege is gained through the Fleet Server’s service account token
CVSS
- Version: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
- Base score: 7.2
Exploitation probability (EPSS)
- Probability of exploitation in the next 30 days: 1.25%
- Percentile among all scored CVEs: 68
- Score date: 10/5/2026
EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).
🎯 ATT&CK techniques
How this vulnerability is exploited and what the attacker gains, in MITRE ATT&CK terms.
- Exploitation
T1210Exploitation of Remote Serviceslateral movement75 % - Primary impact
T1059Command and Scripting Interpreterexecution80 %
Deserialización YAML en servicio remoto Kibana (requiere PR:H y acceso a índices/privilegios específicos). Ejecución de código arbitrario al procesar payload malicioso.
Inferred by our analysis agent from the official description, CVSS vector and CWE, and checked by a supervisor. May contain errors.
🛡️ ATT&CK mitigations that cover these techniques
Affected technologies (1)
CWEs
- CWE-502
References
Raw JSON (NVD)
Show
{
"id": "CVE-2024-37285",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2024-37285",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "yes"
},
{
"technicalImpact": "total"
}
],
"version": "2.0.3",
"timestamp": "2024-11-14T18:46:46.588026Z"
}
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "security@elastic.co",
"cvssData": {
"scope": "CHANGED",
"version": "3.1",
"baseScore": 9.1,
"attackVector": "NETWORK",
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "HIGH",
"confidentialityImpact": "HIGH"
},
"impactScore": 6,
"exploitabilityScore": 2.3
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 7.2,
"attackVector": "NETWORK",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "HIGH",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 1.2
}
]
},
"affected": [
{
"source": "security@elastic.co",
"affectedData": [
{
"vendor": "Elastic",
"product": "Kibana",
"versions": [
{
"status": "affected",
"version": "8.10.0",
"versionType": "semver",
"lessThanOrEqual": "8.15.0"
}
],
"defaultStatus": "unaffected"
}
]
},
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"affectedData": [
{
"cpes": [
"cpe:2.3:a:elastic:kibana:-:*:*:*:*:*:*:*"
],
"vendor": "elastic",
"product": "kibana",
"versions": [
{
"status": "affected",
"version": "8.10.0",
"versionType": "semver",
"lessThanOrEqual": "8.15.0"
}
],
"defaultStatus": "unknown"
}
]
}
],
"published": "2024-11-14T17:15:06.457",
"references": [
{
"url": "https://discuss.elastic.co/t/kibana-8-15-1-security-update-esa-2024-27-esa-2024-28/366119",
"tags": [
"Patch",
"Vendor Advisory"
],
"source": "security@elastic.co"
}
],
"vulnStatus": "Analyzed",
"weaknesses": [
{
"type": "Secondary",
"source": "security@elastic.co",
"description": [
{
"lang": "en",
"value": "CWE-502"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "A deserialization issue in Kibana can lead to arbitrary code execution when Kibana attempts to parse a YAML document containing a crafted payload. A successful attack requires a malicious user to have a combination of both specific Elasticsearch indices privileges https://www.elastic.co/guide/en/elasticsearch/reference/current/defining-roles.html#roles-indices-priv and Kibana privileges https://www.elastic.co/guide/en/fleet/current/fleet-roles-and-privileges.html assigned to them.\n\n\n\nThe following Elasticsearch indices permissions are required\n\n * write privilege on the system indices .kibana_ingest*\n * The allow_restricted_indices flag is set to true\n\n\nAny of the following Kibana privileges are additionally required\n\n * Under Fleet the All privilege is granted\n * Under Integration the Read or All privilege is granted\n * Access to the fleet-setup privilege is gained through the Fleet Server’s service account token"
},
{
"lang": "es",
"value": "Un problema de deserialización en Kibana puede provocar la ejecución de código arbitrario cuando Kibana intenta analizar un documento YAML que contiene un payload manipulado. Un ataque exitoso requiere que un usuario malintencionado tenga una combinación de privilegios específicos de índices de Elasticsearch https://www.elastic.co/guide/en/elasticsearch/reference/current/defining-roles.html#roles-indices-priv y privilegios de Kibana https://www.elastic.co/guide/en/fleet/current/fleet-roles-and-privileges.html asignados a ellos. Se requieren los siguientes permisos de índices de Elasticsearch * privilegio de escritura en los índices del sistema .kibana_ingest* * El indicador allow_restricted_indices está configurado en verdadero Cualquiera de los siguientes privilegios de Kibana también se requiere * En Fleet, se otorga el privilegio All * En Integration, se otorga el privilegio Read o All * El acceso al privilegio de configuración de la flota se obtiene a través del token de cuenta de servicio del servidor Fleet"
}
],
"lastModified": "2026-06-17T07:38:04.550",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:elastic:kibana:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "A43056B3-82DB-47C7-83C9-79C1E628221C",
"versionEndIncluding": "8.15.0",
"versionStartIncluding": "8.10.0"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "security@elastic.co"
}