CyberRota Analysis
AI-GeneratedKibana is vulnerable to a denial-of-service attack due to improper handling of highly compressed data, allowing an authenticated user with Streams management privileges to submit specially crafted content that significantly increases memory allocation. This can lead to the termination of the Kibana process, rendering the service unavailable until it is manually restarted. Organizations using Kibana, especially those with user roles that include Streams management, should prioritize addressing this vulnerability to prevent service disruptions.
Original NVD Description
Improper Handling of Highly Compressed Data (CWE-409) in Kibana can lead to a denial of service via Excessive Allocation (CAPEC-130). An authenticated user holding Streams management privileges could supply specially crafted content that expands to a far larger volume of data during processing, exhausting the memory available to Kibana. The Kibana process is terminated by the host and remains unavailable to all users until the service is restarted.
Related CVEs
Other vulnerabilities affecting the same vendor(s)