CyberRota Analysis
AI-GeneratedKibana contains a missing authorization vulnerability that allows authenticated users to access and modify Cloud Connect configurations and service settings without proper privileges, due to insufficient protection of certain endpoints. This could lead to unauthorized changes and potential disruption of services. Organizations using Kibana should prioritize addressing this issue to safeguard their configurations and maintain proper access controls.
Original NVD Description
Missing Authorization (CWE-862) in Kibana allows an authenticated user to access and modify Cloud Connect configuration and service settings without the required feature privileges, via direct requests to insufficiently protected product endpoints.
Related CVEs
Other vulnerabilities affecting the same vendor(s)