Elastic Kibana
cpe:2.3:a:elastic:kibana:*:*:*:*:*:*:*
- >= 8.0.0, <= 8.19.10
- >= 9.0.0, <= 9.2.4
A vulnerability allowing uncontrolled resource consumption has been identified in the Timelion component of Kibana. This issue can lead to a denial-of-service condition by manipulating input data. The vulnerability affects all Timelion visualizations by default.
Exploitation of this vulnerability causes a denial-of-service condition, where the application becomes unresponsive or unavailable.
Users can upgrade to Kibana versions 8.19.11 or 9.2.5, where this vulnerability has been patched. For users who cannot upgrade and do not use Timelion visualizations, the plugin can be disabled by adding 'vis_type_timelion.enabled: false' to the 'kibana.yml' configuration file. However, this option is not available for Elastic Cloud Hosted customers, who should prioritize upgrading to a patched version.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.