CVE-2020-7016
27.07.2020, 18:15
Kibana versions before 6.8.11 and 7.8.1 contain a denial of service (DoS) flaw in Timelion. An attacker can construct a URL that when viewed by a Kibana user can lead to the Kibana process consuming large amounts of CPU and becoming unresponsive.Enginsight
Vendor | Product | Version |
---|---|---|
elasticsearch | kibana | 𝑥 < 6.8.11 |
elasticsearch | kibana | 7.0.0 ≤ 𝑥 < 7.8.1 |
oracle | communications_billing_and_revenue_management | 12.0.0.3.0 |
oracle | communications_cloud_native_core_network_function_cloud_native_environment | 1.7.0 |
oracle | peoplesoft_enterprise_peopletools | 8.58 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
- CWE-185 - Incorrect Regular ExpressionThe software specifies a regular expression in a way that causes data to be improperly matched or compared.
- CWE-400 - Uncontrolled Resource ConsumptionThe software does not properly control the allocation and maintenance of a limited resource, thereby enabling an actor to influence the amount of resources consumed, eventually leading to the exhaustion of available resources.
References