Vulnerability Description
A server side request forgery vulnerability was identified in Kibana where the /api/fleet/health_check API could be used to send requests to internal endpoints. Due to the nature of the underlying request, only endpoints available over https that return JSON could be accessed. This can be carried out by users with read access to Fleet.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Elastic | Kibana | >= 8.7.0, < 8.15.0 |
Related Weaknesses (CWE)
References
- https://discuss.elastic.co/t/kibana-8-15-0-security-update-esa-2024-29-esa-2024-Issue TrackingPatchVendor Advisory
FAQ
What is CVE-2024-43710?
CVE-2024-43710 is a vulnerability with a CVSS score of 4.3 (MEDIUM). A server side request forgery vulnerability was identified in Kibana where the /api/fleet/health_check API could be used to send requests to internal endpoints. Due to the nature of the underlying req...
How severe is CVE-2024-43710?
CVE-2024-43710 has been rated MEDIUM with a CVSS base score of 4.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-43710?
Check the references section above for vendor advisories and patch information. Affected products include: Elastic Kibana.