Impact
Uncontrolled resource consumption (CWE-400) in Kibana allows an attacker to cause excessive allocation of system resources, resulting in denial of service. The attack compromises the availability of the Kibana service but does not directly affect confidentiality or integrity of data processed by the service.
Affected Systems
Elastic Kibana is the affected product. The CNA data does not specify a vulnerable version, so any current installation of Kibana is potentially affected until the vendor releases an update. All deployments of Kibana from Elastic should be considered at risk.
Risk and Exploitability
The CVSS score of 6.5 indicates medium severity. EPSS is not available, so the likelihood of exploitation cannot be quantified. The vulnerability is not listed in the CISA KEV catalog, implying no documented exploitation at this time. Based on the description, it is inferred that the attack vector is a specially crafted request delivered over the network to an exposed Kibana endpoint.
OpenCVE Enrichment