First published: Thu May 13 2021(Updated: )
Kibana versions before 7.12.1 contain a denial of service vulnerability was found in the webhook actions due to a lack of timeout or a limit on the request size. An attacker with permissions to create webhook actions could drain the Kibana host connection pool, making Kibana unavailable for all other users.
Credit: bressers@elastic.co
Affected Software | Affected Version | How to fix |
---|---|---|
Elastic Kibana | <7.12.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-22139 is a denial of service vulnerability found in Kibana versions before 7.12.1 that allows an attacker to drain the Kibana host connection pool.
CVE-2021-22139 has a severity rating of medium with a score of 6.5.
Kibana versions before 7.12.1 are affected by CVE-2021-22139.
An attacker with permissions to create webhook actions can exploit CVE-2021-22139 by draining the Kibana host connection pool.
Yes, the fix for CVE-2021-22139 is available in Kibana version 7.12.1.