CVE-2020-7016

Severity CVSS v4.0:
Pending analysis
Type:
CWE-400 Uncontrolled Resource Consumption ('Resource Exhaustion')
Publication date:
27/07/2020
Last modified:
16/11/2022

Description

Kibana versions before 6.8.11 and 7.8.1 contain a denial of service (DoS) flaw in Timelion. An attacker can construct a URL that when viewed by a Kibana user can lead to the Kibana process consuming large amounts of CPU and becoming unresponsive.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:elasticsearch:kibana:*:*:*:*:*:*:*:* 6.8.11 (excluding)
cpe:2.3:a:elasticsearch:kibana:*:*:*:*:*:*:*:* 7.0.0 (including) 7.8.1 (excluding)
cpe:2.3:a:oracle:communications_billing_and_revenue_management:12.0.0.3.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:communications_cloud_native_core_network_function_cloud_native_environment:1.7.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools:8.58:*:*:*:*:*:*:*