CyberRota Analysis
AI-GeneratedThe Kibana Osquery feature contains a vulnerability that allows authenticated users with live-query privileges to infer the existence of scheduled query identifiers in unauthorized Kibana spaces. This information disclosure could potentially expose sensitive data or system configurations. Organizations utilizing Kibana, particularly those with multiple user roles and permissions, should prioritize addressing this issue to mitigate the risk of unauthorized information exposure.
Original NVD Description
Observable Response Discrepancy (CWE-204) in the Kibana Osquery feature can lead to information disclosure via Query System for Information (CAPEC-54). An authenticated user holding Osquery live-query privileges could determine whether a scheduled query identifier exists in a Kibana space they are not authorized to access.
Related CVEs
Other vulnerabilities affecting the same vendor(s)