Impact
Allocation of resources without limits in Elastic Kibana can cause excessive memory consumption when an authenticated user with low read-level Agent Builder privileges submits a crafted request. The request forces Kibana to allocate unbounded memory, causing the process to crash and denying service to all users of the instance.
Affected Systems
The vulnerability affects Elastic Kibana. No specific product versions are listed in the provided data, so all installed instances of Kibana are potentially impacted until an update is applied.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity, while the EPSS score is not available and the issue is not listed in CISA KEV. Attackers must be authenticated and possess Agent Builder privileges, which limits the range of attackers but still allows denial of service if exploitation succeeds. Given the lack of exploit data, the likelihood remains uncertain but the potential impact warrants prompt mitigation.
OpenCVE Enrichment