Elastic Kibana
cpe:2.3:a:elastic:kibana:*:*:*:*:*:*:*
- <= 7.17.23
- <= 8.14.2
A denial-of-service vulnerability has been identified in Elastic Kibana versions prior to 7.17.23 and 8.14.2. The issue arises from an unlimited allocation of resources in response to certain requests, specifically to the '/api/log_entries/summary' endpoint. This vulnerability can be exploited by users with read access to the Observability-Logs feature, potentially leading to a crash of the Kibana instance.
Exploitation of this vulnerability causes a crash of the Kibana instance, disrupting service and availability.
Users can upgrade to Kibana versions 7.17.23 or 8.14.2 to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.