Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2024-37288

A deserialization issue in Kibana can lead to arbitrary code execution when Kibana attempts to parse a YAML document containing a crafted payload. This issue only affects users that use Elastic Security’s built-in AI tools https://www.elastic.co/guide/en/security/current/ai-for-security.html  and have configured an Amazon Bedrock connector https://www.elastic.co/guide/en/security/current/assistant-connect-to-bedrock.html .
Exploit prediction scoring system (EPSS) score
EPSS Score 0.013
EPSS Ranking 78.4%
CVSS Severity
CVSS v3 Score 9.9
Products affected by CVE-2024-37288
  • Elastic » Kibana » Version: 8.15.0
    cpe:2.3:a:elastic:kibana:8.15.0


Contact Us

Shodan ® - All rights reserved