First published: Tue Apr 08 2025(Updated: )
An issue has been identified where a specially crafted request sent to an Observability API could cause the kibana server to crash. A successful attack requires a malicious user to have read permissions for Observability assigned to them.
Credit: bressers@elastic.co
Affected Software | Affected Version | How to fix |
---|---|---|
Elastic |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-52974 has been assigned a high severity rating due to its potential to cause server crashes.
To fix CVE-2024-52974, upgrade to the latest version of Elastic Kibana where the vulnerability is patched.
Users of Elastic Kibana with read permissions for Observability are affected by CVE-2024-52974.
CVE-2024-52974 can be exploited by sending a specially crafted request to the Observability API.
There is no official workaround for CVE-2024-52974; updating to a patched version is recommended.