CVE-2017-8452 Vulnerability Details
/
/
/
CVE-2017-8452 Metadata Quick Info
CVE Published: 16/06/2017 |
CVE Updated: 05/08/2024 |
CVE Year: 2017
Source: elastic |
Vendor: Elastic |
Product: Kibana
Status : PUBLISHED
CVE-2017-8452 Description
Kibana versions prior to 5.2.1 configured for SSL client access, file descriptors will fail to be cleaned up after certain requests and will accumulate over time until the process crashes.
Metrics
CVSS Version: 3.1 |
Base Score: n/a
Vector: n/a
l➤ Exploitability Metrics:
Attack Vector (AV)*
Attack Complexity (AC)*
Privileges Required (PR)*
User Interaction (UI)*
Scope (S)*
l➤ Impact Metrics:
Confidentiality Impact (C)*
Integrity Impact (I)*
Availability Impact (A)*
Weakness Enumeration (CWE)
CWE-ID: CWE-775
CWE Name: CWE-775: Missing Release of File Descriptor or Handle after Effective Lifetime
Source: Elastic
Common Attack Pattern Enumeration and Classification (CAPEC)
CAPEC-ID:
CAPEC Description:
Source: NVD (National Vulnerability Database).