{"id":"CVE-2024-43708","details":"An allocation of resources without limits or throttling in Kibana can lead to a crash caused by a specially crafted payload to a number of inputs in Kibana UI. This can be carried out by users with read access to any feature in Kibana.","aliases":["BIT-elk-2024-43708","BIT-kibana-2024-43708"],"modified":"2026-07-22T00:06:02.666966Z","published":"2025-01-23T10:27:30.753Z","database_specific":{"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/43xxx/CVE-2024-43708.json","unresolved_ranges":[{"extracted_events":[{"introduced":"8.0.0"},{"fixed":"8.15.0"},{"introduced":"7.0.0"},{"fixed":"7.17.23"}],"source":"AFFECTED_FIELD"}],"cna_assigner":"elastic","cwe_ids":["CWE-770"]},"references":[{"type":"WEB","url":"https://discuss.elastic.co/t/kibana-7-17-23-8-15-0-security-updates-esa-2024-32-esa-2024-33/373548"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/43xxx/CVE-2024-43708.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-43708"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/elastic/elasticsearch","events":[{"introduced":"0"},{"fixed":"61d76462eecaf09ada684d1b5d319b5ff6865a83"},{"introduced":"1b6a7ece17463df5ff54a3e1302d825889aa1161"},{"fixed":"1a77947f34deddb41af25e6f0ddb8e830159c179"}],"database_specific":{"extracted_events":[{"introduced":"0"},{"fixed":"7.17.23"},{"introduced":"8.0.0"},{"fixed":"8.15.0"}],"source":"CPE_RANGE","cpe":"cpe:2.3:a:elastic:kibana:*:*:*:*:*:*:*:*"}}],"versions":["v7.17.22","v7.17.21","v7.17.20","v7.17.19","v7.17.18","v7.17.17","v7.17.16","v7.17.15","v7.17.14","v7.17.13","v7.17.12","v7.17.11","v7.17.10","v7.17.9","v7.17.8","v7.17.7","v7.17.6","v7.17.5","v7.17.4","v7.17.3","v7.17.2","v7.17.1","v7.17.0","v7.16.1","v7.16.0","v8.0.0-alpha2","v8.0.0-alpha1","v7.0.0-alpha2","v7.0.0-alpha1"],"database_specific":{"vanir_signatures_modified":"2026-07-22T00:06:02Z","vanir_signatures":[{"signature_version":"v1","source":"https://github.com/elastic/elasticsearch/commit/61d76462eecaf09ada684d1b5d319b5ff6865a83","target":{"file":"qa/os/src/test/java/org/elasticsearch/packaging/test/DockerTests.java","function":"test600Interrupt"},"deprecated":false,"digest":{"length":935,"function_hash":"69844453905830246677820397096534298013"},"id":"CVE-2024-43708-3fa86dc6","signature_type":"Function"},{"deprecated":false,"digest":{"function_hash":"142192629617725741299022729598204077325","length":271},"id":"CVE-2024-43708-8673e70a","signature_type":"Function","signature_version":"v1","source":"https://github.com/elastic/elasticsearch/commit/1a77947f34deddb41af25e6f0ddb8e830159c179","target":{"file":"x-pack/plugin/security/src/test/java/org/elasticsearch/xpack/security/authc/ApiKeyServiceTests.java","function":"createThreadPool"}},{"deprecated":false,"digest":{"line_hashes":["90979555117259467445263826000722655414","233880512092644159509098133445422903781","201588729648204699044316536751211233144","150381386453785713982991137249591284441"],"threshold":0.9},"id":"CVE-2024-43708-9c9105ba","signature_type":"Line","signature_version":"v1","source":"https://github.com/elastic/elasticsearch/commit/1a77947f34deddb41af25e6f0ddb8e830159c179","target":{"file":"x-pack/plugin/security/src/main/java/org/elasticsearch/xpack/security/authc/ApiKeyService.java"}},{"signature_type":"Line","signature_version":"v1","source":"https://github.com/elastic/elasticsearch/commit/61d76462eecaf09ada684d1b5d319b5ff6865a83","target":{"file":"qa/os/src/test/java/org/elasticsearch/packaging/test/DockerTests.java"},"deprecated":false,"digest":{"threshold":0.9,"line_hashes":["268439700297186282373755313812072452487","26797522030344409565822344236984547088","49674375891833826585064844018322645796","241861009769944274883436754269135918658","110241150124042836880806124194125742521","4974205076996931494879974579405987532"]},"id":"CVE-2024-43708-bda6ba2f"},{"signature_version":"v1","source":"https://github.com/elastic/elasticsearch/commit/1a77947f34deddb41af25e6f0ddb8e830159c179","target":{"file":"x-pack/plugin/security/src/main/java/org/elasticsearch/xpack/security/authc/ApiKeyService.java","function":"validateApiKeyCredentials"},"deprecated":false,"digest":{"function_hash":"137023518409038292133452283468593548723","length":2537},"id":"CVE-2024-43708-cae71c55","signature_type":"Function"},{"deprecated":false,"digest":{"line_hashes":["203603482067859804637258967793063382345","322917609237158501780418561654099552269","256253239670756748785358014200135771045","315837561795991804971382438615044649236","146427732354523605064218080296921708373","173231181477074759296592300368901057611","61022203414500058386117304455448959197","193300915082347298917541114706348147175","258077855627316307519262695880736716066","125996974648388146940214377483342596447","40188819877500306413169533609100026446","97819836589033936183410863291812511956","28174937397667876549461977660517314954","135344447971163041939327739838227678862","339252469867217754068016957649395888437"],"threshold":0.9},"id":"CVE-2024-43708-fbf59ae4","signature_type":"Line","signature_version":"v1","source":"https://github.com/elastic/elasticsearch/commit/1a77947f34deddb41af25e6f0ddb8e830159c179","target":{"file":"x-pack/plugin/security/src/test/java/org/elasticsearch/xpack/security/authc/ApiKeyServiceTests.java"}}],"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-43708.json"}},{"ranges":[{"type":"GIT","repo":"https://github.com/elastic/kibana","events":[{"introduced":"0"},{"fixed":"89cafc519e1d6e0e08d8cf5c13eee6886fe6e412"},{"introduced":"57ca5e139a33dd2eed927ce98d8231a1f217cd15"},{"fixed":"8aa0b59da12c996e3048d8875446667ee6e15c7f"}],"database_specific":{"cpe":"cpe:2.3:a:elastic:kibana:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"fixed":"7.17.23"},{"introduced":"8.0.0"},{"fixed":"8.15.0"}],"source":"CPE_RANGE"}}],"versions":["deploy@1719814351","deploy@1719209622","deploy@1718616070","deploy@1718000036","v7.17.22","deploy@1717401777","deploy@1717395230","deploy@1716800745","deploy@1716790412","deploy@1716185667","deploy@1715580861","deploy@1714976069","v7.17.21","deploy@1714371303","deploy@1713766425","deploy@1713161715","v7.17.20","deploy@1712566963","deploy@1711952105","deploy@1711370131","v7.17.19","deploy@1710741924","deploy@1710146776","deploy@1710137117","deploy@1709533819","deploy@1709532332","deploy@1708927574","deploy@1708322739","deploy@1707717945","deploy@1707113127","v7.17.18","deploy@1706508321","v7.17.17","deploy@1705903520","deploy@1705306975","deploy@1705298718","deploy@1704693922","deploy@1704089101","deploy@1703484304","deploy@1702903357","deploy@1702879551","deploy@1702367069","deploy@1702284899","v7.17.16","deploy@1701687168","deploy@1701160888","deploy@1700491293","v7.17.15","deploy@1699865290","deploy@1699260155","deploy@1698657637","deploy@1698046713","deploy@1697564183","deploy@1697232175","test-depl-20231025084603","test-depl-20231013154558","deploy@1697028216","deploy@1696873111","deploy@1696618725","v7.17.14","deploy@1696508231","deploy@1696415195","deploy@1696328885","deploy@1695286747","deploy@1694683198","deploy@1694506029","deploy@1694162455","deploy@1694087994","deploy@1693866333","deploy@1693860790","deploy@1693853982","deploy@1693609987","deploy@1693594780","v7.17.13","v7.17.12","v7.17.11","v7.17.10","v7.17.9","v7.17.8","v7.17.7","v7.17.6","v7.17.5","v7.17.4","v7.17.3","v7.17.2","v7.17.1","v7.17.0","v7.16.1","v7.16.0","v8.0.0-alpha2","v8.0.0-alpha1","v7.0.0-alpha2","v7.0.0-alpha1","7.0-known-good","v6.0.0-alpha2","v6.0.0-alpha1","v5.0.0-alpha5","v4.2.0-beta1","v4.0.0-beta3","v4.0.0-beta2","v4.0.0-beta1.1","v4.0.0-beta1"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-43708.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"}]}