CVE-2024-52972: Kibana allocation of resources without limits or throttling leads to crash
An allocation of resources without limits or throttling in Kibana can lead to a crash caused by a specially crafted request to /api/metrics/snapshot. This can be carried out by users with read access to the Observability Metrics or Logs features in Kibana.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2024-52972?
The severity of CVE-2024-52972 is considered high due to its potential to cause a crash in Kibana.
How do I fix CVE-2024-52972?
To fix CVE-2024-52972, update Kibana to the latest version that addresses this vulnerability.
Who is affected by CVE-2024-52972?
Users with read access to the Observability Metrics or Logs features in Kibana are affected by CVE-2024-52972.
What can an attacker do with CVE-2024-52972?
An attacker can exploit CVE-2024-52972 by sending specially crafted requests to /api/metrics/snapshot to cause Kibana to crash.
What versions of Kibana are affected by CVE-2024-52972?
CVE-2024-52972 affects all versions of Kibana prior to the security updates that address this vulnerability.