Lucene search

K
prionPRIOn knowledge basePRION:CVE-2022-23709
HistoryMar 03, 2022 - 10:15 p.m.

Design/Logic Flaw

2022-03-0322:15:00
PRIOn knowledge base
www.prio-n.com
4

4.4 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

22.7%

A flaw was discovered in Kibana in which users with Read access to the Uptime feature could modify alerting rules. A user with this privilege would be able to create new alerting rules or overwrite existing ones. However, any new or modified rules would not be enabled, and a user with this privilege could not modify alerting connectors. This effectively means that Read users could disable existing alerting rules.

CPENameOperatorVersion
kibanaeq8.0.0
kibanage7.7.0
kibanalt7.17.1

4.4 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

22.7%