Impact
Kibana can allocate resources without limits, allowing an authenticated user with lower‑level permissions to submit a crafted request that consumes excessive resources. This flaw is a classic case of resource exhaustion (CWE‑770) and can bring Kibana down, causing a denial of service to legitimate users.
Affected Systems
The vulnerability affects Elastic Kibana. No specific major or minor version is listed, but all installations of Kibana where the default resource limits are not overridden are potentially impacted.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity, and the EPSS score is not available, suggesting no current data on exploitation probability. The weakness is not listed in CISA’s KEV catalog. Exploitation requires authentication with low‑level permissions, so the attacker must be able to log in to Kibana. Once authenticated, the attacker can craft a request that forces Kibana to allocate excessive memory or CPU, leading to service disruption. The attack vector is internal/authenticated and is potentially easier to trigger if default limits are not enforced.
OpenCVE Enrichment