Elasticsearch Kibana Security Update – 11 September 2024

Elasticsearch has released a security update to fix critical vulnerabilities in Kibana versions 8.10.0 to 8.15.0.

The addressed vulnerabilities could allow the remote attacker to execute arbitrary code when Kibana attempts to parse a YAML document containing a crafted payload.

Sample of the addressed vulnerabilities:

Elasticsearch Kibana Remote Code Execution Vulnerability (CVE-2024-37285):

  • CVSS: 9.1
  • Attack Vector: Network
  • Attack Complexity: Low
  • Privileges Required: High
  • User Interaction: None
  • Consequences: Gain Access
Vulnerabilities
  • CVE-2024-37288
  • CVE-2024-37285
Mitigations

The enterprise should deploy this patch as soon as the testing phase is completed.

Elastic Security Advisory

References