356
VMScore

CVE-2021-22139

Published: 13/05/2021 Updated: 21/05/2021
CVSS v2 Base Score: 4 | Impact Score: 2.9 | Exploitability Score: 8
CVSS v3 Base Score: 6.5 | Impact Score: 3.6 | Exploitability Score: 2.8
VMScore: 356
Vector: AV:N/AC:L/Au:S/C:N/I:N/A:P

Vulnerability Summary

Kibana versions prior to 7.12.1 contain a denial of service vulnerability was found in the webhook actions due to a lack of timeout or a limit on the request size. An attacker with permissions to create webhook actions could drain the Kibana host connection pool, making Kibana unavailable for all other users.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

Vendor Advisories

A denial of service vulnerability was found in the Kibana webhook actions due to a lack of timeout or a limit on the request size An attacker with permissions to create webhook actions could drain the Kibana host connection pool, making Kibana unavailable for all other users The issue is fixed in Kibana version 7121 ...