CVE-2024-52974: Medium severity elastic vulnerability
Published Apr 8, 2025
·Updated
An issue has been identified where a specially crafted request sent to an Observability API could cause the kibana server to crash.
A successful attack requires a malicious user to have read permissions for Observability assigned to them.
Affected Software
3 affected components
Elastic Kibana
Elastic Kibana>=7.17.0<7.17.23
Elastic Kibana>=8.0.0<8.15.1
Remediation
Event History
Apr 8, 2025
CVE Published
via MITRE·04:46 PM
Data Sourced
via MITRE·04:46 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·05:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-52974?
CVE-2024-52974 has been assigned a high severity rating due to its potential to cause server crashes.
2
How do I fix CVE-2024-52974?
To fix CVE-2024-52974, upgrade to the latest version of Elastic Kibana where the vulnerability is patched.
3
Who is affected by CVE-2024-52974?
Users of Elastic Kibana with read permissions for Observability are affected by CVE-2024-52974.
4
What kind of attack can exploit CVE-2024-52974?
CVE-2024-52974 can be exploited by sending a specially crafted request to the Observability API.
5
Is there a workaround for CVE-2024-52974?
There is no official workaround for CVE-2024-52974; updating to a patched version is recommended.