Lucene search

K
osvGoogleOSV:CVE-2022-23709
HistoryMar 03, 2022 - 10:15 p.m.

CVE-2022-23709

2022-03-0322:15:08
Google
osv.dev
7

6.5 Medium

AI Score

Confidence

Low

0.001 Low

EPSS

Percentile

22.7%

A flaw was discovered in Kibana in which users with Read access to the Uptime feature could modify alerting rules. A user with this privilege would be able to create new alerting rules or overwrite existing ones. However, any new or modified rules would not be enabled, and a user with this privilege could not modify alerting connectors. This effectively means that Read users could disable existing alerting rules.

6.5 Medium

AI Score

Confidence

Low

0.001 Low

EPSS

Percentile

22.7%