PT-2021-14867 · Elastic · Kibana

Dominic Couture

·

Published

2021-05-13

·

Updated

2021-05-21

·

CVE-2021-22139

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions: Kibana versions prior to 7.12.1
Description: A denial of service issue was found in the webhook actions due to a lack of timeout or a limit on the request size. An attacker with permissions to create webhook actions could drain the Kibana host connection pool, making Kibana unavailable for all other users.
Recommendations: For versions prior to 7.12.1, update to version 7.12.1 or later to resolve the issue. As a temporary workaround, consider restricting access to create webhook actions to minimize the risk of exploitation.

Fix

DoS

Resource Exhaustion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-22139

Affected Products

Kibana