Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2024-23443

Опубликовано: 14 июн. 2024
Источник: redhat
CVSS3: 4.9
EPSS Низкий

Описание

A high-privileged user, allowed to create custom osquery packs 17 could affect the availability of Kibana by uploading a maliciously crafted osquery pack.

A flaw was found in Kibana. A high-privileged user, allowed to create custom osquery packs, could affect the availability of Kibana by uploading a maliciously crafted osquery pack.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Logging Subsystem for Red Hat OpenShiftopenshift-logging/cluster-logging-rhel8-operatorUnder investigation
Logging Subsystem for Red Hat OpenShiftopenshift-logging/elasticsearch-rhel8-operatorUnder investigation
Logging Subsystem for Red Hat OpenShiftopenshift-logging/kibana6-rhel8Under investigation
Red Hat OpenShift Container Platform 3.11kibanaNot affected
Red Hat OpenShift Container Platform 3.11openshift3/ose-logging-kibana5Under investigation
Red Hat OpenStack Platform 16.1puppet-kibana3Under investigation
Red Hat OpenStack Platform 16.2puppet-kibana3Under investigation

Показывать по

Дополнительная информация

Статус:

Moderate
https://bugzilla.redhat.com/show_bug.cgi?id=2292364kibana: uncontrolled resource consumption

EPSS

Процентиль: 84%
0.02217
Низкий

4.9 Medium

CVSS3

Связанные уязвимости

CVSS3: 4.9
nvd
больше 1 года назад

A high-privileged user, allowed to create custom osquery packs 17 could affect the availability of Kibana by uploading a maliciously crafted osquery pack.

CVSS3: 4.9
debian
больше 1 года назад

A high-privileged user, allowed to create custom osquery packs 17 coul ...

CVSS3: 4.9
github
больше 1 года назад

A high-privileged user, allowed to create custom osquery packs 17 could affect the availability of Kibana by uploading a maliciously crafted osquery pack.

EPSS

Процентиль: 84%
0.02217
Низкий

4.9 Medium

CVSS3