Impact
This vulnerability allows an authenticated user to send a request with an oversized input to Kibana’s Entity Analytics endpoints, causing the system to allocate more resources than it can handle. The resulting excessive consumption can make Kibana unavailable, effectively denying service to legitimate users. The weakness is a classic example of resource exhaustion (CWE‑770).
Affected Systems
Elastic Kibana is affected. No specific version information is provided.
Risk and Exploitability
The CVSS score of 6.5 indicates a moderate severity. The EPSS score of less than 1 % suggests a low current likelihood of exploitation. Although the vulnerability is not listed in the CISA KEV catalog, it remains a concern for environments where users have authenticated access to the Analytics endpoints. An attacker with valid credentials can trigger the denial of service by crafting an oversized payload, which makes this risk significant for systems that rely on high availability of Kibana.
OpenCVE Enrichment