Kibana Server Crash Vulnerability in Elastic Observability API
CVE-2024-52974
6.5MEDIUM
What is CVE-2024-52974?
A vulnerability has been detected within the Elastic Observability API that allows a specifically crafted request to cause the Kibana server to crash. This requires an attacker to possess read permissions for the Observability features of Kibana, enabling them to exploit the flaw. Users are advised to be aware of this risk and consider applying security patches offered by Elastic to mitigate potential threats.
Affected Version(s)
Kibana 7.17.0 <= 7.17.22
Kibana 8.0.0 <= 8.15.0