漏洞描述 Elastic Kibana是Elastic公司的一个可用数据可视化仪表板软件。 Elastic Kibana 7.17.0版本至7.17.22版本和8.0.0版本至8.15.0版本存在资源管理错误漏洞,该漏洞源于处理特制请求至 Observability API时存在缺陷,可能导致服务器崩溃。
相关漏洞推荐 Elastic Cloud Enterprise 访问控制不当漏洞 可导致权限提升 POC CVE-2014-3120: ElasticSearch v1.1.1/1.2 RCE POC CVE-2015-1427: ElasticSearch - Remote Code Execution POC CVE-2015-3337: Elasticsearch - Local File Inclusion POC CVE-2015-5531: ElasticSearch <1.6.1 - Local File Inclusion POC CVE-2018-17246: Kibana - Local File Inclusion POC CVE-2019-7609: Kibana Timelion - Arbitrary Code Execution POC CVE-2021-22145: Elasticsearch 7.10.0-7.13.3 - Information Disclosure POC CVE-2022-22733: Apache ShardingSphere ElasticJob-UI privilege escalation POC CVE-2014-3120: ElasticSearch v1.1.1/1.2 RCE POC CVE-2015-1427: ElasticSearch - Remote Code Execution POC CVE-2015-3337: Elasticsearch File Read POC CVE-2015-5531: Elasticsearch CVE-2015-5531