An allocation of resources without limits or throttling in Kibana can lead to a crash caused by a specially crafted request to /api/metrics/snapshot. This can be carried out by users with read access to the Observability Metrics or Logs features in Kibana.
{
"cwe_ids": [
"CWE-770"
],
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/52xxx/CVE-2024-52972.json",
"cna_assigner": "elastic",
"unresolved_ranges": [
{
"source": "AFFECTED_FIELD",
"extracted_events": [
{
"introduced": "8.0.0"
},
{
"fixed": "8.15.0"
},
{
"introduced": "7.0.0"
},
{
"fixed": "7.17.23"
}
]
}
]
}{
"cpe": "cpe:2.3:a:elastic:kibana:*:*:*:*:*:*:*:*",
"source": "CPE_RANGE",
"extracted_events": [
{
"introduced": "0"
},
{
"fixed": "7.17.23"
},
{
"introduced": "8.0.0"
},
{
"fixed": "8.15.0"
}
]
}"2026-07-16T00:24:41Z"
[
{
"signature_type": "Function",
"target": {
"file": "qa/os/src/test/java/org/elasticsearch/packaging/test/DockerTests.java",
"function": "test600Interrupt"
},
"deprecated": false,
"source": "https://github.com/elastic/elasticsearch/commit/61d76462eecaf09ada684d1b5d319b5ff6865a83",
"id": "CVE-2024-52972-3fa86dc6",
"signature_version": "v1",
"digest": {
"function_hash": "69844453905830246677820397096534298013",
"length": 935.0
}
},
{
"signature_type": "Function",
"target": {
"file": "x-pack/plugin/security/src/test/java/org/elasticsearch/xpack/security/authc/ApiKeyServiceTests.java",
"function": "createThreadPool"
},
"deprecated": false,
"source": "https://github.com/elastic/elasticsearch/commit/1a77947f34deddb41af25e6f0ddb8e830159c179",
"id": "CVE-2024-52972-8673e70a",
"signature_version": "v1",
"digest": {
"function_hash": "142192629617725741299022729598204077325",
"length": 271.0
}
},
{
"signature_type": "Line",
"target": {
"file": "x-pack/plugin/security/src/main/java/org/elasticsearch/xpack/security/authc/ApiKeyService.java"
},
"deprecated": false,
"source": "https://github.com/elastic/elasticsearch/commit/1a77947f34deddb41af25e6f0ddb8e830159c179",
"id": "CVE-2024-52972-9c9105ba",
"signature_version": "v1",
"digest": {
"line_hashes": [
"90979555117259467445263826000722655414",
"233880512092644159509098133445422903781",
"201588729648204699044316536751211233144",
"150381386453785713982991137249591284441"
],
"threshold": 0.9
}
},
{
"signature_type": "Line",
"target": {
"file": "qa/os/src/test/java/org/elasticsearch/packaging/test/DockerTests.java"
},
"deprecated": false,
"source": "https://github.com/elastic/elasticsearch/commit/61d76462eecaf09ada684d1b5d319b5ff6865a83",
"id": "CVE-2024-52972-bda6ba2f",
"signature_version": "v1",
"digest": {
"line_hashes": [
"268439700297186282373755313812072452487",
"26797522030344409565822344236984547088",
"49674375891833826585064844018322645796",
"241861009769944274883436754269135918658",
"110241150124042836880806124194125742521",
"4974205076996931494879974579405987532"
],
"threshold": 0.9
}
},
{
"signature_type": "Function",
"target": {
"file": "x-pack/plugin/security/src/main/java/org/elasticsearch/xpack/security/authc/ApiKeyService.java",
"function": "validateApiKeyCredentials"
},
"deprecated": false,
"source": "https://github.com/elastic/elasticsearch/commit/1a77947f34deddb41af25e6f0ddb8e830159c179",
"id": "CVE-2024-52972-cae71c55",
"signature_version": "v1",
"digest": {
"function_hash": "137023518409038292133452283468593548723",
"length": 2537.0
}
},
{
"signature_type": "Line",
"target": {
"file": "x-pack/plugin/security/src/test/java/org/elasticsearch/xpack/security/authc/ApiKeyServiceTests.java"
},
"deprecated": false,
"source": "https://github.com/elastic/elasticsearch/commit/1a77947f34deddb41af25e6f0ddb8e830159c179",
"id": "CVE-2024-52972-fbf59ae4",
"signature_version": "v1",
"digest": {
"line_hashes": [
"203603482067859804637258967793063382345",
"322917609237158501780418561654099552269",
"256253239670756748785358014200135771045",
"315837561795991804971382438615044649236",
"146427732354523605064218080296921708373",
"173231181477074759296592300368901057611",
"61022203414500058386117304455448959197",
"193300915082347298917541114706348147175",
"258077855627316307519262695880736716066",
"125996974648388146940214377483342596447",
"40188819877500306413169533609100026446",
"97819836589033936183410863291812511956",
"28174937397667876549461977660517314954",
"135344447971163041939327739838227678862",
"339252469867217754068016957649395888437"
],
"threshold": 0.9
}
}
]
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-52972.json"
{
"cpe": "cpe:2.3:a:elastic:kibana:*:*:*:*:*:*:*:*",
"source": "CPE_RANGE",
"extracted_events": [
{
"introduced": "0"
},
{
"fixed": "7.17.23"
},
{
"introduced": "8.0.0"
},
{
"fixed": "8.15.0"
}
]
}