Related Vulnerabilities: CVE-2020-7016  

Kibana versions before 6.8.11 and 7.8.1 contain a denial of service (DoS) flaw in Timelion. An attacker can construct a URL that when viewed by a Kibana user can lead to the Kibana process consuming large amounts of CPU and becoming unresponsive.

Severity Medium

Remote Yes

Type Denial of service

Description

Kibana versions before 6.8.11 and 7.8.1 contain a denial of service (DoS) flaw in Timelion. An attacker can construct a URL that when viewed by a Kibana user can lead to the Kibana process consuming large amounts of CPU and becoming unresponsive.

AVG-1210 kibana 7.7.0-1 High Vulnerable

https://discuss.elastic.co/t/elastic-stack-6-8-11-and-7-8-1-security-update/242786