Server Side Request Forgery in Kibana by Elastic
CVE-2024-43710
4.3MEDIUM
What is CVE-2024-43710?
A server side request forgery vulnerability was discovered in Kibana, allowing users with read access to the Fleet feature to exploit the /api/fleet/health_check API. This security flaw enables the sending of unauthorized requests to internal endpoints over HTTPS, targeting those that return JSON responses. It is crucial for users of Kibana to update their systems and review access controls to mitigate potential risks associated with this vulnerability.
Affected Version(s)
Kibana 8.7.0 < 8.15.0