Impact
The vulnerability allows an authenticated user with low-level privileges to send a crafted request that causes Kibana to allocate an unbounded amount of memory, which can exhaust system resources and make the service unavailable to all users. This results in a denial of service through excessive resource consumption (CWE-770).
Affected Systems
Elastic Kibana is affected. The exact product version was not provided in the input, but the advisory indicates that versions before the security update contain the flaw.
Risk and Exploitability
The CVSS score of 6.5 indicates a medium severity vulnerability. No EPSS score is available, suggesting insufficient data to quantify exploitation probability. The vulnerability is not listed in CISA KEV, so no evidence of active exploitation is known. The attack vector requires authentication with low-level privileges, and the exploit depends on the ability to submit a specially crafted request to Kibana.
OpenCVE Enrichment