**Summary:** A prototype pollution in Kibana can be used to gain remote code execution.
**Description:**
There is a prototype pollution bug in the upgrade assistant's telemetry collector, via a dangerous usage of `_.set`: https://github.com/elastic/kibana/blob/master/x-pack/plugins/upgrade_assist…