Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2024-37279


A flaw was discovered in Kibana, allowing view-only users of alerting to use the run_soon API making the alerting rule run continuously, potentially affecting the system availability if the alerting rule is running complex queries.


Published

2024-06-13T17:15:50.770

Last Modified

2025-03-13T16:15:20.190

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 4.3 (MEDIUM)

Weaknesses
  • Type: Primary
    NVD-CWE-Other
  • Type: Secondary
    CWE-284

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application elastic kibana < 8.14.0 Yes

References