High severity8.7NVD Advisory· Published Apr 8, 2025· Updated Jun 17, 2026
CVE-2024-12556
CVE-2024-12556
Description
Prototype Pollution in Kibana can lead to code injection via unrestricted file upload combined with path traversal.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
5- osv-coords2 versions
>= 8.16.1, < 8.17.1+ 1 more
- (no CPE)range: >= 8.16.1, < 8.17.1
- (no CPE)range: >= 8.16.1, < 8.17.1
Patches
Vulnerability mechanics
References
1- discuss.elastic.co/t/kibana-8-16-4-and-8-17-2-security-update-esa-2025-02/376918nvdPatchVendor Advisory
News mentions
0No linked articles in our index yet.