CVE-2017-8452: Elastic Kibana

High severity, CVSS 7.5. EPSS: 1.4% chance of exploitation in the next 30 days.

Kibana versions prior to 5.2.1 configured for SSL client access, file descriptors will fail to be cleaned up after certain requests and will accumulate over time until the process crashes.

Affected products

  • Elastic Kibana: up to and including 5.2.0

Published 2017-06-16. Last modified 2026-06-17.