Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2022-23709

Опубликовано: 28 фев. 2022
Источник: redhat
CVSS3: 4.3
EPSS Низкий

Описание

A flaw was discovered in Kibana in which users with Read access to the Uptime feature could modify alerting rules. A user with this privilege would be able to create new alerting rules or overwrite existing ones. However, any new or modified rules would not be enabled, and a user with this privilege could not modify alerting connectors. This effectively means that Read users could disable existing alerting rules.

A flaw was found in Kibana. This issue allows users with read access to the Uptime feature to modify alerting rules, allowing them to create new or overwrite existing ones. However, any rules created this way are not enabled by default and allow the user to disable an existing, enabled alert rule.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Logging Subsystem for Red Hat OpenShiftopenshift-logging/elasticsearch-rhel8-operatorWill not fix
Logging Subsystem for Red Hat OpenShiftopenshift-logging/kibana6-rhel8Will not fix
Red Hat JBoss Fuse 6KibanaOut of support scope
Red Hat JBoss Fuse Service Works 6KibanaOut of support scope
Red Hat OpenShift Container Platform 3.11kibanaWill not fix
Red Hat OpenShift Container Platform 3.11openshift3/ose-logging-kibana5Will not fix
Red Hat OpenShift Container Platform 4openshift4/ose-elasticsearch-operatorFix deferred
Red Hat OpenShift Container Platform 4openshift4/ose-logging-kibana6Fix deferred
Red Hat OpenStack Platform 13 (Queens)puppet-kibana3Out of support scope
Red Hat OpenStack Platform 16.1puppet-kibana3Not affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-862
https://bugzilla.redhat.com/show_bug.cgi?id=2066386kibana: missing authorization issue (ESA-2022-03)

EPSS

Процентиль: 36%
0.00152
Низкий

4.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 4.3
nvd
почти 4 года назад

A flaw was discovered in Kibana in which users with Read access to the Uptime feature could modify alerting rules. A user with this privilege would be able to create new alerting rules or overwrite existing ones. However, any new or modified rules would not be enabled, and a user with this privilege could not modify alerting connectors. This effectively means that Read users could disable existing alerting rules.

CVSS3: 4.3
debian
почти 4 года назад

A flaw was discovered in Kibana in which users with Read access to the ...

CVSS3: 4.3
github
почти 4 года назад

A flaw was discovered in Kibana in which users with Read access to the Uptime feature could modify alerting rules. A user with this privilege would be able to create new alerting rules or overwrite existing ones. However, any new or modified rules would not be enabled, and a user with this privilege could not modify alerting connectors. This effectively means that Read users could disable existing alerting rules.

EPSS

Процентиль: 36%
0.00152
Низкий

4.3 Medium

CVSS3