Security Advisory

CVE-2024-52974

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2025-04-08 16:46:44
Last updated 2025-04-08 19:59:21
Assigner elastic
CVSS score 6.5
State PUBLISHED

Description

An issue has been identified where a specially crafted request sent to an Observability API could cause the kibana server to crash. A successful attack requires a malicious user to have read permissions for Observability assigned to them.