Ce mail provient de l'extérieur, restons vigilants

=====================================================================

                            CERT-Renater

                Note d'Information No. 2025/VULN348

_____________________________________________________________________

DATE                : 11/06/2025

HARDWARE PLATFORM(S): /

OPERATING SYSTEM(S): Systems running Kibana versions prior to 8.12.1.

=====================================================================
https://discuss.elastic.co/t/kibana-8-12-1-security-update-esa-2024-21/379064
_____________________________________________________________________


Kibana 8.12.1 Security Update (ESA-2024-21)
Announcements Security Announcements
rodrigo_silva (Rodrigo Silva) June 10, 2025, 4:48pm 1

Kibana Improper Authorization (ESA-2024-21)

Improper authorization in Kibana can lead to privilege abuse via a
direct HTTP request to a Synthetic monitor endpoint.


Affected Versions:

Kibana versions before and including 8.12.0.


Solutions and Mitigations:

The issue is resolved in versions 8.12.1.

For Users that Cannot Upgrade:

Self-hosted:
Users with a self-hosted deployment who cannot upgrade can disable the
synthetics app OR put a block on synthetics indices.

    Disable the synthetics by adding xpack.uptime.enabled: false to
their kibana.yml file
    Put an index block on the synthetics-* indices to make them
read-only see

Elastic Cloud:
Users on an Elastic Cloud deployment who cannot upgrade can put a
block on synthetics indices

    Put an index block on the synthetics-* indices to make them
read-only see


Severity: High(7.6) - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:L/CR:M/IR:M/AR:M
CVE ID: CVE-2024-43706


=========================================================
+ CERT-RENATER        |    tel : 01-53-94-20-44         +
+ 23/25 Rue Daviel    |    fax : 01-53-94-20-41         +
+ 75013 Paris         |   email:cert@support.renater.fr +
=========================================================
