← Back

CVE-2024-43707

nvd nist
Published: Jan 23, 2025Modified: Sep 30, 2025

JSON object

Loading...
6.5
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Exploitability: 2.8 / Impact: 3.6
Source: NVD

Description

An issue was identified in Kibana where a user without access to Fleet can view Elastic Agent policies that could contain sensitive information. The nature of the sensitive information depends on the integrations enabled for the Elastic Agent and their respective versions.

Affected (1)

Products: Elastic: Kibana
1 product
Kibana
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
From 8.7.0 to 8.15.0

References (1)

Source: security@elastic.co
Issue TrackingPatchVendor Advisory

Timeline

No history available yet.