CVE-2024-43710 - CVE House
Back to Database
Status published Medium CVE-2024-43710

Kibana server-side request forgery

Vulnerability Description

A server side request forgery vulnerability was identified in Kibana where the /api/fleet/health_check API could be used to send requests to internal endpoints. Due to the nature of the underlying request, only endpoints available over https that return JSON could be accessed. This can be carried out by users with read access to Fleet.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-43710

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

Kibana
Vulnerable Versions:
8.7.0

Timeline

Official Publish: January 23rd, 2025
Last Modified: January 23rd, 2025
Added to House: July 22nd, 2026

CVSS Vectors

V3: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N

Weaknesses (CWE)