Elastic Kibana
cpe:2.3:a:elastic:kibana:*:*:*:*:*:*:*
- <= 7.17.22
- <= 8.14.3
A denial-of-service vulnerability has been identified in Elastic Kibana, specifically in versions through 7.17.22 and 8.0.0 up to 8.14.3. The issue arises from an allocation of resources without proper limits or throttling, which can lead to a crash. This vulnerability can be exploited by users with read access to the Observability Metrics or Logs features in Kibana, through a specially crafted request to the '/api/metrics/snapshot' endpoint.
Exploitation of this vulnerability causes Kibana to crash, disrupting the application's availability and potentially leading to a denial-of-service condition.
Users can upgrade to Kibana versions 7.17.23 or 8.15.0 to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.