Kibana versions before 6.8.11 and 7.8.1 contain a denial of service (DoS) flaw in Timelion. An attacker can construct a URL that when viewed by a Kibana user can lead to the Kibana process consuming large amounts of CPU and becoming unresponsive.
2020-07-27T18:15:14.170
2024-11-21T05:36:29.940
Modified
CVSSv3.1: 4.8 (MEDIUM)
AV:N/AC:H/Au:S/C:N/I:N/A:P
3.9
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | elasticsearch | kibana | < 6.8.11 | Yes |
Application | elasticsearch | kibana | < 7.8.1 | Yes |
Application | oracle | communications_billing_and_revenue_management | 12.0.0.3.0 | Yes |
Application | oracle | communications_cloud_native_core_network_function_cloud_native_environment | 1.7.0 | Yes |
Application | oracle | peoplesoft_enterprise_peopletools | 8.58 | Yes |