Lucene search

K
cvelistElasticCVELIST:CVE-2020-7016
HistoryJul 27, 2020 - 6:00 p.m.

CVE-2020-7016

2020-07-2718:00:15
CWE-185
elastic
www.cve.org
9
kibana
denial of service
timelion
cpu consumption
unresponsive

AI Score

5.6

Confidence

High

EPSS

0.001

Percentile

35.4%

Kibana versions before 6.8.11 and 7.8.1 contain a denial of service (DoS) flaw in Timelion. An attacker can construct a URL that when viewed by a Kibana user can lead to the Kibana process consuming large amounts of CPU and becoming unresponsive.

CNA Affected

[
  {
    "product": "Kibana",
    "vendor": "Elastic",
    "versions": [
      {
        "status": "affected",
        "version": "before 6.8.11 and 7.8.1"
      }
    ]
  }
]

AI Score

5.6

Confidence

High

EPSS

0.001

Percentile

35.4%