CVE-2020-7016: Medium severity kibana vulnerability
Published Jul 27, 2020
·Updated
Kibana versions before 6.8.11 and 7.8.1 contain a denial of service (DoS) flaw in Timelion. An attacker can construct a URL that when viewed by a Kibana user can lead to the Kibana process consuming large amounts of CPU and becoming unresponsive.
Affected Software
5 affected components
Elasticsearch Kibana<6.8.11
Elasticsearch Kibana>=7.0.0<7.8.1
Oracle Communications Billing and Revenue Management=12.0.0.3.0
Oracle Communications Cloud Native Core Network Function Cloud Native Environment=1.7.0
Oracle PeopleSoft Enterprise PeopleTools=8.58
Remediation
Patch Available
Event History
Jul 27, 2020
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this Kibana flaw?
The vulnerability ID for this Kibana flaw is CVE-2020-7016.
2
What is the impact of CVE-2020-7016?
The impact of CVE-2020-7016 is a denial of service (DoS) vulnerability that can cause the Kibana process to consume large amounts of CPU and become unresponsive.
3
Which versions of Kibana are affected by CVE-2020-7016?
Versions before 6.8.11 and 7.8.1 of Kibana are affected by CVE-2020-7016.
4
What is the severity of CVE-2020-7016?
The severity of CVE-2020-7016 is medium, with a severity value of 4.8.
5
How can I fix the vulnerability CVE-2020-7016?
To fix the vulnerability CVE-2020-7016, it is recommended to upgrade to Kibana version 6.8.11 or 7.8.1.