Search

published date: June 10, 2025

CVE-2024-43706 : Improper Authorization Vulnerability

Elastic Kibana

Description

Improper authorization in Kibana can lead to privilege abuse via a direct HTTP request to a Synthetic monitor endpoint.

Product(s):

  • Elastic Kibana 4.1.0
  • Elastic Kibana 4.1.1
  • Elastic Kibana 4.2.0
  • Elastic Kibana 4.2.1
  • Elastic Kibana 4.3.0
  • Elastic Kibana 4.3.1

Question to Ask Vendors:

  1. Have you updated all instances of Kibana to version 8.12.1 or later to mitigate the risk of CVE-2024-43706, which allows unauthorized access to synthetic monitoring data and actions?
  2. Can you confirm if you have disabled the Synthetic Monitoring feature (xpack.uptime.enabled: false in kibana.yml) in all instances of Kibana where it is not in use, as recommended in the advisory?
  3. Have you implemented network restrictions to limit Kibana HTTP access to trusted IPs or via secure proxy, as a mitigation measure against the improper authorization flaw in Kibana's Synthetic Monitoring feature?
  4. Have you reviewed and tightened your RBAC definitions to ensure only intended roles can access Synthetic Monitoring, and have you set all synthetics-* indices to read-only via dynamic index blocks to prevent unauthorized writes?

READY TO GET RESULTS YOU CAN TRUST?