Deserialization vulnerability in Kibana can lead to arbitrary code execution
CVE-2024-37288
Key Information:
Badges
What is CVE-2024-37288?
A vulnerability in Kibana has been identified, stemming from a deserialization issue that may allow for arbitrary code execution. This flaw occurs specifically when Kibana attempts to process a maliciously crafted YAML document. Only instances of Kibana that leverage Elastic Security’s integrated AI tools and have seamlessly configured an Amazon Bedrock connector are impacted. Users of these features should exercise caution and apply security updates to mitigate potential risks associated with this vulnerability.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Kibana 8.15.0
News Articles
References
CVSS V3.1
Timeline
- đź“°
First article discovered by CybersecurityNews
Vulnerability published
Vulnerability Reserved