Deserialization vulnerability in Kibana can lead to arbitrary code execution
CVE-2024-37288
8.8HIGH
Key Information:
Badges
đź“° News Worthy
What is CVE-2024-37288?
A vulnerability in Kibana has been identified, stemming from a deserialization issue that may allow for arbitrary code execution. This flaw occurs specifically when Kibana attempts to process a maliciously crafted YAML document. Only instances of Kibana that leverage Elastic Security’s integrated AI tools and have seamlessly configured an Amazon Bedrock connector are impacted. Users of these features should exercise caution and apply security updates to mitigate potential risks associated with this vulnerability.
Affected Version(s)
Kibana 8.15.0