Elastic Kibana
cpe:2.3:a:elastic:kibana:*:*:*:*:*:*:*
- >= 8.19.0, < 8.19.14
- >= 9.2.0, < 9.2.8
- >= 9.3.0, < 9.3.3
A denial-of-service vulnerability has been identified in Elastic Kibana versions 8.19.14, 9.2.8, and 9.3.3. This issue arises from uncontrolled resource consumption, allowing an authenticated user with access to the automatic import feature to send requests with excessively large input values. When multiple such requests are sent concurrently, the backend services become unstable, causing service disruptions and making the deployment unavailable for all users.
Excessive resource allocation from concurrent requests can destabilize backend services, leading to service disruptions and unavailability for users.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.