CyberRota Analysis
AI-GeneratedKibana is vulnerable to an authorization bypass that allows authenticated users to access alerting rule execution telemetry from spaces they should not have permission to view. This can lead to unauthorized information disclosure, including sensitive data such as rule identifiers and execution outcomes. Organizations using Kibana, particularly those managing multiple spaces with varying access controls, should prioritize addressing this vulnerability to protect sensitive telemetry data.
Original NVD Description
Authorization Bypass Through User-Controlled Key (CWE-639) in Kibana can lead to information disclosure via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). An authenticated user who is authorized to read alerting rules in a single Kibana space could retrieve alerting rule execution telemetry that belongs to spaces the user is not authorized to access. The disclosed telemetry includes rule identifiers, rule names, space identifiers, execution outcomes, timestamps, and execution counters.