CVE-2022-23709
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
03/03/2022
Last modified:
16/03/2022
Description
A flaw was discovered in Kibana in which users with Read access to the Uptime feature could modify alerting rules. A user with this privilege would be able to create new alerting rules or overwrite existing ones. However, any new or modified rules would not be enabled, and a user with this privilege could not modify alerting connectors. This effectively means that Read users could disable existing alerting rules.
Impact
Base Score 3.x
4.30
Severity 3.x
MEDIUM
Base Score 2.0
4.00
Severity 2.0
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:elastic:kibana:*:*:*:*:*:*:*:* | 7.7.0 (including) | 7.17.1 (excluding) |
| cpe:2.3:a:elastic:kibana:8.0.0:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



