PT-2021-14867 · Elastic · Kibana
Dominic Couture
·
Published
2021-05-13
·
Updated
2021-05-21
·
CVE-2021-22139
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions:
Kibana versions prior to 7.12.1
Description:
A denial of service issue was found in the webhook actions due to a lack of timeout or a limit on the request size. An attacker with permissions to create webhook actions could drain the Kibana host connection pool, making Kibana unavailable for all other users.
Recommendations:
For versions prior to 7.12.1, update to version 7.12.1 or later to resolve the issue. As a temporary workaround, consider restricting access to create webhook actions to minimize the risk of exploitation.
Fix
DoS
Resource Exhaustion
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Kibana