Impact
Observable Response Discrepancy (CWE-204) in the Kibana Osquery feature enables an authenticated user who holds live‑query privileges to determine whether a scheduled query identifier exists in a Kibana space they are not authorized to access. The vulnerability can reveal the presence of scheduled queries across spaces, enabling attackers to enumerate sensitive data or configuration details. The impact is an information disclosure that compromises confidentiality within the affected Kibana environment.
Affected Systems
Elastic Kibana is affected. No specific version information was supplied, so all installations that include the Osquery feature may be subject to this vulnerability until a patch is released.
Risk and Exploitability
The CVSS score of 4.3 indicates a moderate impact. EPSS data is not available, and the vulnerability is not listed in CISA's KEV catalog. Exploitation requires authentication with live‑query privileges, so the attack vector is limited to authenticated users. An attacker with such privileges can enumerate scheduled queries across spaces, but no remote code execution or denial of service is possible. The overall risk is moderate, with a realistic likelihood that an attacker could leverage existing credentials to gain additional hidden information.
OpenCVE Enrichment