A flaw was discovered in Kibana, allowing view-only users of alerting to use the run_soon API making the alerting rule run continuously, potentially affecting the system availability if the alerting rule is running complex queries.
{
"cpes": [
"cpe:2.3:a:elasticsearch:kibana:*:*:*:*:*:*:*:*",
"cpe:2.3:a:elasticsearch:kibana:*:*:*:*:*:node.js:*:*"
],
"severity": "Medium"
}