# Kibana 7.17.23/8.14.0 Security Update (ESA-2024-16)

**URL:** <https://discuss.elastic.co/t/kibana-7-17-23-8-14-0-security-update-esa-2024-16/364094>\
**Category:** Security Announcements\
**Created:** [July 30, 2024, 9:22pm UTC](https://discuss.elastic.co/t/kibana-7-17-23-8-14-0-security-update-esa-2024-16/364094 "2024-07-30T21:22:31Z")\
**Posts on this page:** 1\
**Showing post:** 1

<div class="post-metadata">

**Author:** ![Bryan\_Garcia](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bryan_garcia/32/148179_2.png) [@Bryan\_Garcia](https://discuss.elastic.co/u/Bryan_Garcia)\
**Post date:** [July 30, 2024, 9:22pm UTC](https://discuss.elastic.co/t/kibana-7-17-23-8-14-0-security-update-esa-2024-16/364094/1 "2024-07-30T21:22:31Z")

</div>

Kibana Denial of Service issue (ESA-2024-16)

An issue was discovered in Kibana where a user with Viewer role could cause a Kibana instance to crash by sending a large number of maliciously crafted requests to a specific endpoint.

Affected Versions:  
Kibana 8.x versions prior to 8.14.0 and Kibana 7.x versions prior to 7.17.23

Solutions and Mitigations:  
The issue is resolved in version 8.14.0 and 7.17.23.

Severity: CVSSv3: 6.5(Medium) - AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H/CR:M/IR:M/AR:M  
CVE ID: CVE-2024-37281

---

_[View the full topic](https://discuss.elastic.co/t/kibana-7-17-23-8-14-0-security-update-esa-2024-16/364094)._
