Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2024-37279

Опубликовано: 05 июн. 2024
Источник: redhat
CVSS3: 4.3
EPSS Низкий

Описание

A flaw was discovered in Kibana, allowing view-only users of alerting to use the run_soon API making the alerting rule run continuously, potentially affecting the system availability if the alerting rule is running complex queries.

A flaw was discovered in Kibana, allowing read-only alerting users using the run_soon API making the alerting rule run continuously. This issue potentially affects the system if the alerting rule is running complex queries.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Logging Subsystem for Red Hat OpenShiftopenshift-logging/cluster-logging-rhel8-operatorAffected
Logging Subsystem for Red Hat OpenShiftopenshift-logging/elasticsearch-rhel8-operatorAffected
Logging Subsystem for Red Hat OpenShiftopenshift-logging/kibana6-rhel8Affected
Red Hat OpenShift Container Platform 3.11kibanaOut of support scope
Red Hat OpenShift Container Platform 3.11openshift3/ose-logging-kibana5Out of support scope
Red Hat OpenStack Platform 16.1puppet-kibana3Out of support scope
Red Hat OpenStack Platform 16.2puppet-kibana3Out of support scope

Показывать по

Дополнительная информация

Статус:

Moderate
https://bugzilla.redhat.com/show_bug.cgi?id=2290676kibana: read-only alerting users using the run_soon API making the alerting rule run continuously

EPSS

Процентиль: 32%
0.00124
Низкий

4.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 4.3
nvd
больше 1 года назад

A flaw was discovered in Kibana, allowing view-only users of alerting to use the run_soon API making the alerting rule run continuously, potentially affecting the system availability if the alerting rule is running complex queries.

CVSS3: 4.3
debian
больше 1 года назад

A flaw was discovered in Kibana, allowing view-only users of alerting ...

CVSS3: 4.3
github
больше 1 года назад

A flaw was discovered in Kibana, allowing view-only users of alerting to use the run_soon API making the alerting rule run continuously, potentially affecting the system availability if the alerting rule is running complex queries.

EPSS

Процентиль: 32%
0.00124
Низкий

4.3 Medium

CVSS3