Show filters
185 Total Results
Displaying 1-10 of 185
Sort by:
Attacker Value
Unknown

CVE-2019-7609

Disclosure Date: March 25, 2019 (last updated July 25, 2024)
Kibana versions before 5.6.15 and 6.6.1 contain an arbitrary code execution flaw in the Timelion visualizer. An attacker with access to the Timelion application could send a request that will attempt to execute javascript code. This could possibly lead to an attacker executing arbitrary commands with permissions of the Kibana process on the host system.
Attacker Value
Unknown

CVE-2024-43708

Disclosure Date: January 23, 2025 (last updated January 23, 2025)
An allocation of resources without limits or throttling in Kibana can lead to a crash caused by a specially crafted payload to a number of inputs in Kibana UI. This can be carried out by users with read access to any feature in Kibana.
0
Attacker Value
Unknown

CVE-2024-52975

Disclosure Date: January 23, 2025 (last updated January 23, 2025)
An issue was identified in Fleet Server where Fleet policies that could contain sensitive information were logged on INFO and ERROR log levels. The nature of the sensitive information largely depends on the integrations enabled.
0
Attacker Value
Unknown

CVE-2024-52972

Disclosure Date: January 23, 2025 (last updated January 23, 2025)
An allocation of resources without limits or throttling in Kibana can lead to a crash caused by a specially crafted request to /api/metrics/snapshot. This can be carried out by users with read access to the Observability Metrics or Logs features in Kibana.
0
Attacker Value
Unknown

CVE-2024-43710

Disclosure Date: January 23, 2025 (last updated January 23, 2025)
A server side request forgery vulnerability was identified in Kibana where the /api/fleet/health_check API could be used to send requests to internal endpoints. Due to the nature of the underlying request, only endpoints available over https that return JSON could be accessed. This can be carried out by users with read access to Fleet.
0
Attacker Value
Unknown

CVE-2024-43707

Disclosure Date: January 23, 2025 (last updated January 23, 2025)
An issue was identified in Kibana where a user without access to Fleet can view Elastic Agent policies that could contain sensitive information. The nature of the sensitive information depends on the integrations enabled for the Elastic Agent and their respective versions.
0
Attacker Value
Unknown

CVE-2024-52973

Disclosure Date: January 21, 2025 (last updated January 21, 2025)
An allocation of resources without limits or throttling in Kibana can lead to a crash caused by a specially crafted request to /api/log_entries/summary. This can be carried out by users with read access to the Observability-Logs feature in Kibana.
0
Attacker Value
Unknown

CVE-2024-43709

Disclosure Date: January 21, 2025 (last updated February 01, 2025)
An allocation of resources without limits or throttling in Elasticsearch can lead to an OutOfMemoryError exception resulting in a crash via a specially crafted query using an SQL function.
Attacker Value
Unknown

CVE-2024-37284

Disclosure Date: January 21, 2025 (last updated January 21, 2025)
Improper handling of alternate encoding occurs when Elastic Defend on Windows systems attempts to scan a file or process encoded as a multibyte character. This leads to an uncaught exception causing Elastic Defend to crash which in turn will prevent it from quarantining the file and/or killing the process.
0
Attacker Value
Unknown

CVE-2024-12539

Disclosure Date: December 17, 2024 (last updated February 05, 2025)
An issue was discovered where improper authorization controls affected certain queries that could allow a malicious actor to circumvent Document Level Security in Elasticsearch and get access to documents that their roles would normally not allow.