This exploit is beautiful in every aspect CVE-2019-7609. Upgrade your Kibana. https://www.tenable.com/blog/cve-2019-7609-exploit-script-available-for-kibana-remote-code-execution-vulnerability #kibana #security #javascript #nodejs
@saper Yeah, Michał came up with not so romantic name for it!
@kravietz was it more like #!$(@#)$ btw. https://slides.com/securitymb/prototype-pollution-in-kibana#/25 is oversimiplification
@kravietz #javascriptshock?