Horizon Alert
Summary of the vulnerability and why it matters
A critical vulnerability in Fleet Server, which is part of Kibana, could allow an attacker to inject and execute malicious scripts. This happens because the system does not properly validate identifiers used in server-side scripts during agent policy processing, potentially leading to unauthorized code execution.
- Code injection flaw in Fleet Server technology.
- Matters due to potential for unauthorized script execution.
- Confirm relevance and exposure are the main concerns.
Attack Path
How an attacker could exploit the issue
An attacker could exploit this vulnerability by sending a specially crafted identifier to Kibana, which is then processed by Fleet Server. This identifier, when embedded within a server-side script during agent policy setup, allows the attacker's script content to be executed. This could lead to unauthorized code execution on the server.
- No authentication or user interaction required.
- Vulnerable component processes attacker-controlled identifier.
- Risk of attacker-supplied script execution.
Live Threat
Current exploitation, exposure, and threat context
Fleet Server, when processing agent policies, could execute attacker-supplied script content if a specially crafted identifier is provided for an output configuration. This occurs because the identifier is embedded directly into a server-side script without proper sanitization, allowing script syntax to be interpreted as executable code rather than data.
- Server-side scripts and agent policy processing.
- An identifier in an output configuration.
- Execution of unauthorized script content.
Operational Fix
Recommended remediation, mitigation, and detection steps
Application owners, likely within infrastructure or platform teams managing Kibana and Fleet Server, are responsible for addressing this critical code injection vulnerability. The immediate priority is to identify all instances of the affected Kibana versions, confirm their exposure and criticality, and then coordinate remediation efforts. This may involve vendor engagement with Elastic and careful planning for maintenance windows or implementing temporary compensating controls to mitigate risk until a permanent fix can be applied.
- Confirm Kibana and Fleet Server ownership.
- Verify exposure and business criticality.
- Plan vendor-coordinated remediation.