Vulnerability CVE-2017-8452


Published: 2017-06-16

Description:
Kibana versions prior to 5.2.1 configured for SSL client access, file descriptors will fail to be cleaned up after certain requests and will accumulate over time until the process crashes.

Type:

CWE-769

CVSS2 => (AV:N/AC:L/Au:N/C:N/I:N/A:P)

CVSS Base Score
Impact Subscore
Exploitability Subscore
5/10
2.9/10
10/10
Exploit range
Attack complexity
Authentication
Remote
Low
No required
Confidentiality impact
Integrity impact
Availability impact
None
None
Partial
Affected software
Elasticsearch -> Kibana 

 References:
https://www.elastic.co/community/security

Copyright 2024, cxsecurity.com

 

Back to Top