CVE-2024-23443: Medium severity elastic vulnerability
Published Jun 19, 2024
·Updated
A high-privileged user, allowed to create custom osquery packs 17 could affect the availability of Kibana by uploading a maliciously crafted osquery pack.
Affected Software
2 affected components
Elastic Kibana>=7.0.0<7.17.22
Elastic Kibana>=8.0.0<8.14.0
Event History
Jun 19, 2024
CVE Published
via MITRE·01:47 PM
Data Sourced
via MITRE·01:47 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·02:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-23443?
CVE-2024-23443 is considered a high severity vulnerability due to the potential to affect the availability of Kibana.
2
How do I fix CVE-2024-23443?
To remediate CVE-2024-23443, update Kibana to versions later than 7.17.22 or 8.14.0.
3
Who is affected by CVE-2024-23443?
CVE-2024-23443 affects users of Elastic Kibana versions between 7.0.0 and 7.17.22, and between 8.0.0 and 8.14.0.
4
What type of attack does CVE-2024-23443 enable?
CVE-2024-23443 enables a high-privileged user to upload a malicious osquery pack that can affect the stability of Kibana.
5
Is there a workaround for CVE-2024-23443?
There is no official workaround for CVE-2024-23443; upgrading to a patched version is recommended.