CVE-2024-43710
Kibana server-side request forgery
4.3
MEDIUM
CVSS 3.1
EPSS 0.23%
Description
A server side request forgery vulnerability was identified in Kibana where the /api/fleet/health_check API could be used to send requests to internal endpoints. Due to the nature of the underlying request, only endpoints available over https that return JSON could be accessed. This can be carried out by users with read access to Fleet.
How to fix CVE-2024-43710
To remediate CVE-2024-43710, upgrade the affected package to a fixed version below.
- —upgrade to 8.15.0 or later
- —upgrade to 8.15.0 or later
Is CVE-2024-43710 being exploited?
Low — EPSS is 0.2%, meaning exploitation activity has not been observed at scale.
Affected packages (2)
- >= 8.7.0, < 8.15.0
- >= 8.7.0, < 8.15.0
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | MEDIUM4.3 | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N |