Kibana versions before 7.12.1 contain a denial of service vulnerability was found in the webhook actions due to a lack of timeout or a limit on the request size. An attacker with permissions to create webhook actions could drain the Kibana host connection pool, making Kibana unavailable for all other users.
[
{
"deprecated": false,
"source": "https://github.com/elastic/elasticsearch/commit/3186837139b9c6b6d23c3200870651f10d3343b7",
"id": "CVE-2021-22139-0c9f23b2",
"signature_type": "Function",
"target": {
"file": "x-pack/plugin/runtime-fields/src/main/java/org/elasticsearch/xpack/runtimefields/query/DoubleScriptFieldRangeQuery.java",
"function": "matches"
},
"digest": {
"function_hash": "177997335789464563202284736183893757219",
"length": 196.0
},
"signature_version": "v1"
},
{
"deprecated": false,
"source": "https://github.com/elastic/elasticsearch/commit/3186837139b9c6b6d23c3200870651f10d3343b7",
"id": "CVE-2021-22139-569d0a24",
"signature_type": "Line",
"target": {
"file": "x-pack/plugin/runtime-fields/src/test/java/org/elasticsearch/xpack/runtimefields/query/DoubleScriptFieldRangeQueryTests.java"
},
"digest": {
"threshold": 0.9,
"line_hashes": [
"37279048494127768418954148874196692472",
"313488571969326042757844282764190141468",
"117742873420922048707046160517471385535",
"102562244793221056205671480676951616228"
]
},
"signature_version": "v1"
},
{
"deprecated": false,
"source": "https://github.com/elastic/elasticsearch/commit/3186837139b9c6b6d23c3200870651f10d3343b7",
"id": "CVE-2021-22139-f01faa57",
"signature_type": "Line",
"target": {
"file": "x-pack/plugin/runtime-fields/src/main/java/org/elasticsearch/xpack/runtimefields/query/DoubleScriptFieldRangeQuery.java"
},
"digest": {
"threshold": 0.9,
"line_hashes": [
"28504398628265692451926817695278896234",
"159888689223021119038564351952697837832",
"195675636153053807690031180436552871031",
"136156030778886982672439852222274120398"
]
},
"signature_version": "v1"
},
{
"deprecated": false,
"source": "https://github.com/elastic/elasticsearch/commit/3186837139b9c6b6d23c3200870651f10d3343b7",
"id": "CVE-2021-22139-fc038bf0",
"signature_type": "Function",
"target": {
"file": "x-pack/plugin/runtime-fields/src/test/java/org/elasticsearch/xpack/runtimefields/query/DoubleScriptFieldRangeQueryTests.java",
"function": "testMatches"
},
"digest": {
"function_hash": "165459211770947153635316298123984953502",
"length": 604.0
},
"signature_version": "v1"
}
]