An issue was discovered in Kibana where a user with Viewer role could cause a Kibana instance to crash by sending a large number of maliciously crafted requests to a specific endpoint.
[
{
"id": "CVE-2024-37281-3fa86dc6",
"source": "https://github.com/elastic/elasticsearch/commit/61d76462eecaf09ada684d1b5d319b5ff6865a83",
"signature_type": "Function",
"target": {
"file": "qa/os/src/test/java/org/elasticsearch/packaging/test/DockerTests.java",
"function": "test600Interrupt"
},
"deprecated": false,
"signature_version": "v1",
"digest": {
"length": 935.0,
"function_hash": "69844453905830246677820397096534298013"
}
},
{
"id": "CVE-2024-37281-bda6ba2f",
"source": "https://github.com/elastic/elasticsearch/commit/61d76462eecaf09ada684d1b5d319b5ff6865a83",
"signature_type": "Line",
"target": {
"file": "qa/os/src/test/java/org/elasticsearch/packaging/test/DockerTests.java"
},
"deprecated": false,
"signature_version": "v1",
"digest": {
"line_hashes": [
"268439700297186282373755313812072452487",
"26797522030344409565822344236984547088",
"49674375891833826585064844018322645796",
"241861009769944274883436754269135918658",
"110241150124042836880806124194125742521",
"4974205076996931494879974579405987532"
],
"threshold": 0.9
}
}
]