CyberRota Analysis
AI-GeneratedThe Kibana machine learning feature contains a vulnerability that allows users with only read access to execute operations using an internal service identity, potentially leading to unauthorized information disclosure from Elasticsearch indices. This privilege abuse could expose sensitive data to users who should not have access, making it critical for organizations utilizing Kibana to prioritize remediation efforts. Security teams should assess their Kibana configurations and user access controls to mitigate this risk.
Original NVD Description
Execution with Unnecessary Privileges (CWE-250) in the Kibana machine learning feature can lead to information disclosure via Privilege Abuse (CAPEC-122). An operation available to users holding only read access to the machine learning feature was performed with an internal service identity rather than the identity of the requesting user. Such a user could therefore receive data from Elasticsearch indices they are not authorized to read. No Elasticsearch cluster or index privileges are required.
Related CVEs
Other vulnerabilities affecting the same vendor(s)