CVE-2024-43707
Kibana exposure of sensitive information to an unauthorized actor
6.5
MEDIUM
CVSS 3.1
EPSS 0.41%
Description
An issue was identified in Kibana where a user without access to Fleet can view Elastic Agent policies that could contain sensitive information. The nature of the sensitive information depends on the integrations enabled for the Elastic Agent and their respective versions.
How to fix CVE-2024-43707
To remediate CVE-2024-43707, upgrade the affected package to a fixed version below.
- —upgrade to 8.15.0 or later
- —upgrade to 8.15.0 or later
Is CVE-2024-43707 being exploited?
Low — EPSS is 0.4%, meaning exploitation activity has not been observed at scale.
Affected packages (2)
- >= 8.0.0, < 8.15.0
- >= 8.0.0, < 8.15.0
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | MEDIUM6.5 | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |