SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2021-22139

Kibana versions before 7.12.1 contain a denial of service vulnerability was found in the webhook actions due to a lack of timeout or a limit on the request size.

MEDIUM 6.5EPSS 1.00%

Does this matter?

Lower severity and a low EPSS score (1.00%). Track it; it rarely justifies an emergency change on its own.

Description

Kibana versions before 7.12.1 contain a denial of service vulnerability was found in the webhook actions due to a lack of timeout or a limit on the request size. An attacker with permissions to create webhook actions could drain the Kibana host connection pool, making Kibana unavailable for all other users.

CVSS 3.1
6.5 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
EPSS
1.00% probability · 61th percentile
CISA KEV
Not listed
Weakness
CWE-400
Affected
elastic/kibana
Source
security@elastic.co

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.