Elastic Kibana
cpe:2.3:a:elastic:kibana:*:*:*:*:*:*:*
- ~7
- ~8.0.0, <= 8.19.8
- ~9.0.0, <= 9.1.8
- ~9.2.0, <= 9.2.2
A resource exhaustion vulnerability has been identified in Elastic Kibana, specifically in versions 7.x, 8.x prior to 8.19.9, and 9.x prior to 9.2.3. This vulnerability allows a low-privileged authenticated user to send a crafted HTTP request that causes excessive allocation of computing resources, leading to a denial-of-service condition where the Kibana process becomes unresponsive.
Exploitation of this vulnerability causes a denial-of-service condition, where the Kibana process is overwhelmed and becomes unresponsive.
Users can upgrade to Kibana versions 8.19.9, 9.1.9, or 9.2.3 to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.