CVE-2017-8452

Kibana versions prior to 5.2.1 configured for SSL client access, file descriptors will fail to be cleaned up after certain requests and will accumulate over time until the process crashes.
References
Link Resource
https://www.elastic.co/community/security Vendor Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:elastic:kibana:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2017-06-16 21:29

Updated : 2024-02-04 19:29


NVD link : CVE-2017-8452

Mitre link : CVE-2017-8452

CVE.ORG link : CVE-2017-8452


JSON object : View

Products Affected

elastic

  • kibana
CWE
CWE-769

DEPRECATED: Uncontrolled File Descriptor Consumption

CWE-775

Missing Release of File Descriptor or Handle after Effective Lifetime