CVE-2022-23709

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
03/03/2022
Last modified:
16/03/2022

Description

A flaw was discovered in Kibana in which users with Read access to the Uptime feature could modify alerting rules. A user with this privilege would be able to create new alerting rules or overwrite existing ones. However, any new or modified rules would not be enabled, and a user with this privilege could not modify alerting connectors. This effectively means that Read users could disable existing alerting rules.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:elastic:kibana:*:*:*:*:*:*:*:* 7.7.0 (including) 7.17.1 (excluding)
cpe:2.3:a:elastic:kibana:8.0.0:*:*:*:*:*:*:*