{"id":"CVE-2021-22139","details":"Kibana versions before 7.12.1 contain a denial of service vulnerability was found in the webhook actions due to a lack of timeout or a limit on the request size. An attacker with permissions to create webhook actions could drain the Kibana host connection pool, making Kibana unavailable for all other users.","modified":"2026-07-08T23:57:54.284454Z","published":"2021-05-13T18:15:09.120Z","references":[{"type":"ADVISORY","url":"https://discuss.elastic.co/t/7-12-1-security-update/271433"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/elastic/elasticsearch","events":[{"introduced":"0"},{"fixed":"3186837139b9c6b6d23c3200870651f10d3343b7"}],"database_specific":{"cpe":"cpe:2.3:a:elastic:kibana:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"fixed":"7.12.1"}],"source":"CPE_RANGE"}}],"versions":["v7.12.0","v7.0.0-alpha2","v7.0.0-alpha1"],"database_specific":{"vanir_signatures":[{"deprecated":false,"digest":{"function_hash":"177997335789464563202284736183893757219","length":196},"id":"CVE-2021-22139-0c9f23b2","signature_type":"Function","signature_version":"v1","source":"https://github.com/elastic/elasticsearch/commit/3186837139b9c6b6d23c3200870651f10d3343b7","target":{"function":"matches","file":"x-pack/plugin/runtime-fields/src/main/java/org/elasticsearch/xpack/runtimefields/query/DoubleScriptFieldRangeQuery.java"}},{"target":{"file":"x-pack/plugin/runtime-fields/src/test/java/org/elasticsearch/xpack/runtimefields/query/DoubleScriptFieldRangeQueryTests.java"},"deprecated":false,"digest":{"line_hashes":["37279048494127768418954148874196692472","313488571969326042757844282764190141468","117742873420922048707046160517471385535","102562244793221056205671480676951616228"],"threshold":0.9},"id":"CVE-2021-22139-569d0a24","signature_type":"Line","signature_version":"v1","source":"https://github.com/elastic/elasticsearch/commit/3186837139b9c6b6d23c3200870651f10d3343b7"},{"source":"https://github.com/elastic/elasticsearch/commit/3186837139b9c6b6d23c3200870651f10d3343b7","target":{"file":"x-pack/plugin/runtime-fields/src/main/java/org/elasticsearch/xpack/runtimefields/query/DoubleScriptFieldRangeQuery.java"},"deprecated":false,"digest":{"line_hashes":["28504398628265692451926817695278896234","159888689223021119038564351952697837832","195675636153053807690031180436552871031","136156030778886982672439852222274120398"],"threshold":0.9},"id":"CVE-2021-22139-f01faa57","signature_type":"Line","signature_version":"v1"},{"signature_type":"Function","signature_version":"v1","source":"https://github.com/elastic/elasticsearch/commit/3186837139b9c6b6d23c3200870651f10d3343b7","target":{"function":"testMatches","file":"x-pack/plugin/runtime-fields/src/test/java/org/elasticsearch/xpack/runtimefields/query/DoubleScriptFieldRangeQueryTests.java"},"deprecated":false,"digest":{"function_hash":"165459211770947153635316298123984953502","length":604},"id":"CVE-2021-22139-fc038bf0"}],"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-22139.json","vanir_signatures_modified":"2026-07-08T23:57:54Z"}},{"ranges":[{"type":"GIT","repo":"https://github.com/elastic/kibana","events":[{"introduced":"0"},{"fixed":"abb04c5543d2201630c9669fe3680864506d924e"}],"database_specific":{"cpe":"cpe:2.3:a:elastic:kibana:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"fixed":"7.12.1"}],"source":"CPE_RANGE"}}],"versions":["v7.12.0","v7.0.0-alpha2","v7.0.0-alpha1","7.0-known-good","v6.0.0-alpha2","v6.0.0-alpha1","v5.0.0-alpha5","v4.2.0-beta1","v4.0.0-beta3","v4.0.0-beta2","v4.0.0-beta1.1","v4.0.0-beta1"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-22139.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"}]}