Home
HIGH: 7.6 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:LDefault status
unaffected
8.12.0 (semver) before 8.12.1
affected
Description
Improper authorization in Kibana can lead to privilege abuse via a direct HTTP request to a Synthetic monitor endpoint.
Problem types
CWE-285: Improper Authorization
Product status
8.12.0 (semver) before 8.12.1
References
discuss.elastic.co/...2-1-security-update-esa-2024-21/379064