An issue has been identified where a specially crafted request sent to an Observability API could cause the kibana server to crash.
A successful attack requires a malicious user to have read permissions for Observability assigned to them.
{
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/52xxx/CVE-2024-52974.json",
"cna_assigner": "elastic",
"unresolved_ranges": [
{
"source": "AFFECTED_FIELD",
"extracted_events": [
{
"introduced": "7.17.0"
},
{
"last_affected": "7.17.22"
},
{
"introduced": "8.0.0"
},
{
"last_affected": "8.15.0"
}
]
}
],
"cwe_ids": [
"CWE-400"
]
}[
{
"digest": {
"length": 935.0,
"function_hash": "69844453905830246677820397096534298013"
},
"signature_version": "v1",
"source": "https://github.com/elastic/elasticsearch/commit/61d76462eecaf09ada684d1b5d319b5ff6865a83",
"signature_type": "Function",
"target": {
"function": "test600Interrupt",
"file": "qa/os/src/test/java/org/elasticsearch/packaging/test/DockerTests.java"
},
"id": "CVE-2024-52974-3fa86dc6",
"deprecated": false
},
{
"digest": {
"threshold": 0.9,
"line_hashes": [
"268439700297186282373755313812072452487",
"26797522030344409565822344236984547088",
"49674375891833826585064844018322645796",
"241861009769944274883436754269135918658",
"110241150124042836880806124194125742521",
"4974205076996931494879974579405987532"
]
},
"signature_version": "v1",
"source": "https://github.com/elastic/elasticsearch/commit/61d76462eecaf09ada684d1b5d319b5ff6865a83",
"signature_type": "Line",
"target": {
"file": "qa/os/src/test/java/org/elasticsearch/packaging/test/DockerTests.java"
},
"id": "CVE-2024-52974-bda6ba2f",
"deprecated": false
}
]
"2026-07-17T19:37:25Z"
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-52974.json"