CVE-2024-52974
EUVD-2025-1027308.04.2025, 17:15
An issue has been identified where a specially crafted request sent to an Observability API could cause the kibana server to crash. A successful attack requires a malicious user to have read permissions for Observability assigned to them.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| elastic | kibana | 7.17.0 ≤ 𝑥 < 7.17.23 |
| elastic | kibana | 8.0.0 ≤ 𝑥 < 8.15.1 |
𝑥
= Vulnerable software versions