CVE-2024-37281: Kibana Denial of Service issue
Published Jul 30, 2024
·Updated
An issue was discovered in Kibana where a user with Viewer role could cause a Kibana instance to crash by sending a large number of maliciously crafted requests to a specific endpoint.
Affected Software
3 affected components
Elastic Kibana
Elastic Kibana>=7.0.0<7.17.23
Elastic Kibana>=8.0.0<8.14.0
Remediation
Event History
Jul 30, 2024
CVE Published
via MITRE·09:45 PM
Data Sourced
via MITRE·09:45 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·10:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-37281?
CVE-2024-37281 is rated as a moderate severity vulnerability that can cause a Kibana instance to crash.
2
How do I fix CVE-2024-37281?
To fix CVE-2024-37281, you should update Kibana to the latest version provided by Elastic that addresses this vulnerability.
3
Who is affected by CVE-2024-37281?
CVE-2024-37281 affects users of Kibana who have the Viewer role, potentially allowing them to exploit the vulnerability.
4
What happens if CVE-2024-37281 is exploited?
Exploitation of CVE-2024-37281 can lead to the crashing of a Kibana instance, disrupting service for users.
5
Is there a workaround for CVE-2024-37281?
There is no official workaround for CVE-2024-37281 other than upgrading to a patched version of Kibana.