CVE-2017-8452

Related Vulnerabilities: CVE-2017-8452  

Kibana versions prior to 5.2.1 configured for SSL client access, file descriptors will fail to be cleaned up after certain requests and will accumulate over time until the process crashes.

The MITRE CVE dictionary describes this issue as:

Kibana versions prior to 5.2.1 configured for SSL client access, file descriptors will fail to be cleaned up after certain requests and will accumulate over time until the process crashes.

Find out more about CVE-2017-8452 from the MITRE CVE dictionary dictionary and NIST NVD.

CVSS v3 metrics

NOTE: The following CVSS v3 metrics and score provided are preliminary and subject to review.

CVSS3 Base Score 5.3
CVSS3 Base Metrics CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Attack Vector Network
Attack Complexity Low
Privileges Required None
User Interaction None
Scope Unchanged
Confidentiality None
Integrity Impact None
Availability Impact Low

Affected Packages State

Platform Package State
Red Hat OpenStack Platform Operational Tools 9 kibana Will not fix
Red Hat OpenStack Platform 10.0 Operational Tools for RHEL 7 kibana Not affected
Red Hat OpenShift Enterprise 3 kibana Will not fix
Red Hat Enterprise Linux OpenStack Platform 8.0 Operational Tools for RHEL 7 kibana Will not fix
Red Hat Enterprise Linux OpenStack Platform 7.0 Operational Tools for RHEL 7 kibana Will not fix