CVE-2024-37281

An issue was discovered in Kibana where a user with Viewer role could cause a Kibana instance to crash by sending a large number of maliciously crafted requests to a specific endpoint.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:elastic:kibana:*:*:*:*:*:*:*:*
cpe:2.3:a:elastic:kibana:*:*:*:*:*:*:*:*

History

29 Sep 2025, 14:09

Type Values Removed Values Added
CPE cpe:2.3:a:elastic:kibana:*:*:*:*:*:*:*:*
First Time Elastic kibana
Elastic
References () https://discuss.elastic.co/t/kibana-7-17-23-8-14-0-security-update-esa-2024-16/364094 - () https://discuss.elastic.co/t/kibana-7-17-23-8-14-0-security-update-esa-2024-16/364094 - Patch, Issue Tracking, Vendor Advisory

21 Nov 2024, 09:23

Type Values Removed Values Added
References () https://discuss.elastic.co/t/kibana-7-17-23-8-14-0-security-update-esa-2024-16/364094 - () https://discuss.elastic.co/t/kibana-7-17-23-8-14-0-security-update-esa-2024-16/364094 -

31 Jul 2024, 12:57

Type Values Removed Values Added
Summary
  • (es) Se descubrió un problema en Kibana donde un usuario con rol de Observador podía provocar que una instancia de Kibana fallara al enviar una gran cantidad de solicitudes manipuladas con fines malintencionados a un endpoint específico.

30 Jul 2024, 22:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-07-30 22:15

Updated : 2025-09-29 14:09


NVD link : CVE-2024-37281

Mitre link : CVE-2024-37281

CVE.ORG link : CVE-2024-37281


JSON object : View

Products Affected

elastic

  • kibana
CWE
CWE-400

Uncontrolled Resource Consumption