PT-2025-2948 · Elastic · Kibana

Published

2024-11-18

·

Updated

2025-01-27

·

CVE-2024-52972

CVSS v2.0

6.8

Medium

VectorAV:N/AC:L/Au:S/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Kibana (affected versions not specified)
Description An allocation of resources without limits or throttling in Kibana can lead to a crash caused by a specially crafted request to "/api/metrics/snapshot". This can be carried out by users with read access to the Observability Metrics or Logs features in Kibana.
Recommendations As a temporary workaround, consider restricting access to the "/api/metrics/snapshot" endpoint until a patch is available. Restrict access to the Observability Metrics or Logs features in Kibana to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Allocation of Resources Without Limits

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-01324
BIT-ELK-2024-52972
BIT-KIBANA-2024-52972
CVE-2024-52972

Affected Products

Kibana