An issue has been identified where a specially crafted request sent to an Observability API could cause the kibana server to crash.
A successful attack requires a malicious user to have read permissions for Observability assigned to them.
| Software | From | Fixed in |
|---|---|---|
| elastic / kibana | 7.17.0 | 7.17.23 |
| elastic / kibana | 8.0.0 | 8.15.1 |