CyberRota Analysis
AI-GeneratedKibana is vulnerable to a denial of service due to an uncaught exception that can be triggered by an authenticated user with low-privileged access through input data manipulation. This flaw allows the user to submit a crafted request that causes the Kibana process to crash, affecting all users and spaces until the service is restarted. Organizations using Kibana, particularly those with low-privileged user access, should prioritize addressing this vulnerability to maintain service availability.
Original NVD Description
Uncaught Exception (CWE-248) in Kibana can lead to a denial of service via Input Data Manipulation (CAPEC-153). An authenticated user holding only the low-privileged feature access required to use the Observability AI Assistant can submit a specially crafted request that produces an unhandled error condition, terminating the Kibana process and denying service to all users and spaces on that instance until it is restarted.
Related CVEs
Other vulnerabilities affecting the same vendor(s)