Impact
An uncaught exception (CWE-248) can occur when a Kibana case comment contains malformed link syntax. The exception is not handled, preventing the case from being displayed for any user that opens it. Consequently, the case becomes permanently inaccessible until the offending comment is removed. This denial of service can affect any use of the impacted Kibana instance.
Affected Systems
Elastic Kibana is affected. No specific version information is provided in the advisory, so all current releases may be vulnerable until a fix is widely deployed.
Risk and Exploitability
The CVSS score of 4.3 indicates moderate severity, and the attack requires an authenticated user with comment privileges who can create a malformed link. There is no EPSS score or KEV designation, suggesting the vulnerability is not currently widely exploited in the wild. The denial of service impact is confined to the affected case, but the lack of a graceful error path raises concern for reliability.
OpenCVE Enrichment