Vulnerability Description
A flaw was discovered in Kibana in which users with Read access to the Uptime feature could modify alerting rules. A user with this privilege would be able to create new alerting rules or overwrite existing ones. However, any new or modified rules would not be enabled, and a user with this privilege could not modify alerting connectors. This effectively means that Read users could disable existing alerting rules.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Elastic | Kibana | >= 7.7.0, < 7.17.1 |
Related Weaknesses (CWE)
References
- https://discuss.elastic.co/t/elastic-stack-7-17-1-security-update/298447Vendor Advisory
- https://discuss.elastic.co/t/elastic-stack-7-17-1-security-update/298447Vendor Advisory
FAQ
What is CVE-2022-23709?
CVE-2022-23709 is a vulnerability with a CVSS score of 4.3 (MEDIUM). A flaw was discovered in Kibana in which users with Read access to the Uptime feature could modify alerting rules. A user with this privilege would be able to create new alerting rules or overwrite ex...
How severe is CVE-2022-23709?
CVE-2022-23709 has been rated MEDIUM with a CVSS base score of 4.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-23709?
Check the references section above for vendor advisories and patch information. Affected products include: Elastic Kibana.