CVE-2024-52974

An issue has been identified where a specially crafted request sent to an Observability API could cause the kibana server to crash. A successful attack requires a malicious user to have read permissions for Observability assigned to them.
References
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:elastic:kibana:*:*:*:*:*:*:*:*
cpe:2.3:a:elastic:kibana:*:*:*:*:*:*:*:*

History

30 Sep 2025, 21:36

Type Values Removed Values Added
References () https://discuss.elastic.co/t/kibana-7-17-23-and-8-15-1-security-update-esa-2024-36/376923 - () https://discuss.elastic.co/t/kibana-7-17-23-and-8-15-1-security-update-esa-2024-36/376923 - Patch, Issue Tracking, Vendor Advisory
First Time Elastic
Elastic kibana
CPE cpe:2.3:a:elastic:kibana:*:*:*:*:*:*:*:*
Summary
  • (es) Se ha identificado un problema en el que una solicitud especialmente manipulada enviada a una API de Observability podría provocar el bloqueo del servidor Kibana. Para que el ataque tenga éxito, se requiere que un usuario malintencionado tenga permisos de lectura asignados a Observability.

08 Apr 2025, 17:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-04-08 17:15

Updated : 2025-09-30 21:36


NVD link : CVE-2024-52974

Mitre link : CVE-2024-52974

CVE.ORG link : CVE-2024-52974


JSON object : View

Products Affected

elastic

  • kibana
CWE
CWE-400

Uncontrolled Resource Consumption