Ce mail provient de l'extérieur, restons vigilants ===================================================================== CERT-Renater Note d'Information No. 2025/VULN033 _____________________________________________________________________ DATE : 22/01/2025 HARDWARE PLATFORM(S): / OPERATING SYSTEM(S): Systems running Kibana versions prior to 7.17.23, 8.14.2. ===================================================================== https://discuss.elastic.co/t/kibana-7-17-23-and-8-14-2-security-update-esa-2024-26/373443 _____________________________________________________________________ Kibana 7.17.23 and 8.14.2 Security Update (ESA-2024-26) Announcements Security Announcements ismisepaul (Paul) January 21, 2025, 10:50am 1 Kibana allocation of resources without limits or throttling leads to crash (ESA-2024-26) An allocation of resources without limits or throttling in Kibana can lead to a crash caused by a specially crafted request to /api/log_entries/summary. This can be carried out by users with read access to the Observability-Logs feature in Kibana. Affected Versions: Kibana up to 7.17.23 and up to 8.14.2 Solutions and Mitigations: The issue is resolved in version 7.17.23 and 8.14.2. Severity: CVSSv3.1: 6.5 (Medium) - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H CVE ID: CVE-2024-52973 ========================================================= + CERT-RENATER | tel : 01-53-94-20-44 + + 23/25 Rue Daviel | fax : 01-53-94-20-41 + + 75013 Paris | email:cert@support.renater.fr + =========================================================