Elastic Kibana
cpe:2.3:a:elastic:kibana:*:*:*:*:*:*:*
- <= 7.17.22
- <= 8.14.3
A denial-of-service vulnerability has been identified in Elastic Kibana, specifically in versions through 7.17.22 and 8.0.0 up to and including 8.14.3. The issue arises from an allocation of resources without proper limits or throttling, allowing users with read access to certain features, such as Observability Metrics or Logs, to send specially crafted requests that can crash the application.
Exploitation of this vulnerability causes Kibana to crash, disrupting service and availability.
Users can upgrade to Kibana versions 7.17.23 or 8.15.0 to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.