Kibana versions before 7.12.1 contain a denial of service vulnerability...
Vulnerability Description
Kibana versions before 7.12.1 contain a denial of service vulnerability was found in the webhook actions due to a lack of timeout or a limit on the request size. An attacker with permissions to create webhook actions could drain the Kibana host connection pool, making Kibana unavailable for all other users.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2021-22139
Credits & Attribution
No credits recorded in the NVD database.
More from Elastic
View All →Affected Vendor
Elastic
View all reports →