CyberRota Analysis
AI-GeneratedKibana is vulnerable to a denial of service due to improper resource allocation, allowing authenticated users with low-level Agent Builder privileges to submit crafted requests that can exhaust memory resources. This can lead to the termination of the Kibana process, impacting all users of the instance. Organizations using Kibana should prioritize addressing this vulnerability to prevent potential service disruptions.
Original NVD Description
Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lead to a denial of service via Excessive Allocation (CAPEC-130). An authenticated user holding only low, read-level Agent Builder privileges could submit a specially crafted request that causes Kibana to consume an unbounded amount of memory, terminating the process and denying service to all users of the instance.
Related CVEs
Other vulnerabilities affecting the same vendor(s)