First published: Tue Jul 30 2024(Updated: )
An issue was discovered in Kibana where a user with Viewer role could cause a Kibana instance to crash by sending a large number of maliciously crafted requests to a specific endpoint.
Credit: bressers@elastic.co
Affected Software | Affected Version | How to fix |
---|---|---|
Elastic |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-37281 is rated as a moderate severity vulnerability that can cause a Kibana instance to crash.
To fix CVE-2024-37281, you should update Kibana to the latest version provided by Elastic that addresses this vulnerability.
CVE-2024-37281 affects users of Kibana who have the Viewer role, potentially allowing them to exploit the vulnerability.
Exploitation of CVE-2024-37281 can lead to the crashing of a Kibana instance, disrupting service for users.
There is no official workaround for CVE-2024-37281 other than upgrading to a patched version of Kibana.