Improper Input Validation (CWE-20) in Kibana's Email Connector can allow an attacker to cause an Excessive Allocation (CAPEC-130) through a specially crafted email address parameter. This requires an attacker to have authenticated access with view-level privileges sufficient to execute connector actions. The application attempts to process specially crafted email format, resulting in complete service unavailability for all users until manual restart is performed.
| Software | From | Fixed in |
|---|---|---|
| elastic / kibana | 7.0.0 | 7.17.29.x |
| elastic / kibana | 8.0.0 | 8.19.0 |
| elastic / kibana | 9.0.0 | 9.1.10 |
| elastic / kibana | 9.2.0 | 9.2.4 |