CVE-2024-43710
Kibana server-side request forgery
4.3
MEDIUM
CVSS 3.1
EPSS 0.23%
描述
A server side request forgery vulnerability was identified in Kibana where the /api/fleet/health_check API could be used to send requests to internal endpoints. Due to the nature of the underlying request, only endpoints available over https that return JSON could be accessed. This can be carried out by users with read access to Fleet.
如何修補 CVE-2024-43710
要修補 CVE-2024-43710,請將受影響套件升級到下列已修補版本。
- —升級至 8.15.0 或更新版本
- —升級至 8.15.0 或更新版本
CVE-2024-43710 正在被利用嗎?
低 — EPSS 為 0.2%,目前沒有觀察到大規模利用活動。
受影響套件(2)
- >= 8.7.0, < 8.15.0
- >= 8.7.0, < 8.15.0
CVSS 分數
| 來源 | 版本 | 嚴重程度 | 向量 |
|---|---|---|---|
| osv | CVSS 3.1 | MEDIUM4.3 | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N |