Resource Allocation Vulnerability in Kibana by Elastic
CVE-2024-52972

6.5MEDIUM

Key Information:

Vendor
Elastic
Status
Vendor
CVE Published:
23 January 2025

Summary

A vulnerability in Kibana allows for resource allocation without proper limits or throttling. This can lead to service disruptions when specially crafted requests are sent to the /api/metrics/snapshot endpoint. Users with read access to the Observability Metrics or Logs features can exploit this flaw, potentially causing the system to crash.

Affected Version(s)

Kibana 8.0.0 < 8.15.0

Kibana 7.0.0 < 7.17.23

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.