Page 3 of 21 results (0.004 seconds)
CVSS: 4.3EPSS: 0%CPEs: 2EXPL: 0

CVE-2022-23709
https://notcve.org/view.php?id=CVE-2022-23709
03 Mar 2022 — A flaw was discovered in Kibana in which users with Read access to the Uptime feature could modify alerting rules. A user with this privilege would be able to create new alerting rules or overwrite existing ones. However, any new or modified rules would not be enabled, and a user with this privilege could not modify alerting connectors. This effectively means that Read users could disable existing alerting rules. Se ha detectado un fallo en Kibana en el que usuarios con acceso de lectura a la función de tie... • https://discuss.elastic.co/t/elastic-stack-7-17-1-security-update/298447 • CWE-264: Permissions, Privileges, and Access Controls CWE-862: Missing Authorization •