VYPR
Unrated severityNVD Advisory· Published Jan 23, 2025· Updated Jan 23, 2025

Kibana exposure of sensitive information to an unauthorized actor

CVE-2024-43707

Description

An issue was identified in Kibana where a user without access to Fleet can view Elastic Agent policies that could contain sensitive information. The nature of the sensitive information depends on the integrations enabled for the Elastic Agent and their respective versions.

Affected products

4

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.