CyberRota Analysis
AI-GeneratedThe vulnerability affects the Kibana Machine Learning feature, allowing users with limited privileges to remove trained models from a space without proper authorization. This could lead to unauthorized modifications of machine learning resources, impacting the integrity of anomaly detection and data frame analytics jobs. Organizations utilizing Kibana for machine learning should prioritize addressing this issue to safeguard their model management processes.
Original NVD Description
A Kibana Machine Learning capability that removes a saved object from the current space accepts machine learning trained models as a target, but it verifies only the privileges that apply to anomaly detection jobs and data frame analytics jobs. A user whose role grants create anomaly detection jobs and data frame analytics jobs without the trained model privilege can therefore remove a trained model from a space. The model itself is not deleted and remains available in its other spaces, and the change can be reversed by a suitably privileged user.