PT-2017-18344 · Elastic · Kibana

Published

2017-06-16

·

Updated

2020-10-19

·

CVE-2017-8452

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Kibana versions prior to 5.2.1
Description The issue affects Kibana when configured for SSL client access. File descriptors will fail to be cleaned up after certain requests, causing them to accumulate over time until the process crashes.
Recommendations For versions prior to 5.2.1, update to version 5.2.1 or later to resolve the issue.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2017-8452

Affected Products

Kibana