CVE-2020-7016
published 2020-07-27CVE-2020-7016: Kibana versions before 6.8.11 and 7.8.1 contain a denial of service (DoS) flaw in Timelion. An attacker can construct a URL that when viewed by a Kibana user…
PriorityP419medium4.8CVSS 3.1
AVNACHPRLUIRSUCNINAH
EPSS
1.08%
61.5th percentile
Kibana versions before 6.8.11 and 7.8.1 contain a denial of service (DoS) flaw in Timelion. An attacker can construct a URL that when viewed by a Kibana user can lead to the Kibana process consuming large amounts of CPU and becoming unresponsive.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| elastic | kibana | — | — |
| elasticsearch | kibana | < 6.8.11 | 6.8.11 |
| elasticsearch | kibana | >= 7.0.0 < 7.8.1 | 7.8.1 |
| oracle | communications_billing_and_revenue_management | — | — |
| oracle | communications_cloud_native_core_network_function_cloud_native_environment | — | — |
| oracle | peoplesoft_enterprise_peopletools | — | — |
CVSS provenance
nvdv3.14.8MEDIUMCVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:N/I:N/A:H
nvdv2.02.1LOWAV:N/AC:H/Au:S/C:N/I:N/A:P
vendor_redhat4.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
kibana: DoS in Timelion
vendor_redhat·2020-07-27·CVSS 4.8
CVE-2020-7016 [MEDIUM] CWE-400 kibana: DoS in Timelion
kibana: DoS in Timelion
Kibana versions before 6.8.11 and 7.8.1 contain a denial of service (DoS) flaw in Timelion. An attacker can construct a URL that when viewed by a Kibana user can lead to the Kibana process consuming large amounts of CPU and becoming unresponsive.
A flaw was found in kibana’s Timelion component. This flaw allows an attacker to construct a URL that can lead to the kibana process consuming large amounts of CPU and becoming unresponsive when viewed by a kibana user. The highest threat from this vulnerability is to system availability.
Statement: In Red Hat OpenShift Container Platform (RHOCP), the affected kibana component is behind OpenShift OAuth authentication. This restricts access to the vulnerable Timelion kibana component to authenticated users only, therefore
GHSA
GHSA-hrj2-4hpm-cjw9: Kibana versions before 6
ghsa_unreviewed·2022-05-24
CVE-2020-7016 [MEDIUM] CWE-400 GHSA-hrj2-4hpm-cjw9: Kibana versions before 6
Kibana versions before 6.8.11 and 7.8.1 contain a denial of service (DoS) flaw in Timelion. An attacker can construct a URL that when viewed by a Kibana user can lead to the Kibana process consuming large amounts of CPU and becoming unresponsive.
No detection rules found.
No public exploits indexed.
https://discuss.elastic.co/t/elastic-stack-6-8-11-and-7-8-1-security-update/242786https://www.elastic.co/community/security/https://www.oracle.com//security-alerts/cpujul2021.htmlhttps://discuss.elastic.co/t/elastic-stack-6-8-11-and-7-8-1-security-update/242786https://www.elastic.co/community/security/https://www.oracle.com//security-alerts/cpujul2021.html
2020-07-27
Published