CVE-2024-37279: Elastic Kibana
Medium severity, CVSS 4.3. EPSS: 0.4% chance of exploitation in the next 30 days.
A flaw was discovered in Kibana, allowing view-only users of alerting to use the run_soon API making the alerting rule run continuously, potentially affecting the system availability if the alerting rule is running complex queries.
Affected products
- Elastic Kibana: from 8.6.3, before 8.14.0 (fixed in 8.14.0)
Published 2024-06-13. Last modified 2026-06-17.