# Kibana 7.17.23/8.15.0 Security Updates (ESA-2024-32, ESA-2024-33)

**URL:** https://discuss.elastic.co/t/kibana-7-17-23-8-15-0-security-updates-esa-2024-32-esa-2024-33/373548
**Category:** Security Announcements
**Created:** [January 23, 2025, 5:52am UTC](https://discuss.elastic.co/t/kibana-7-17-23-8-15-0-security-updates-esa-2024-32-esa-2024-33/373548 "2025-01-23T05:52:11Z")
**Posts on this page:** 1
**Page:** 1

<div class="post-metadata">

### Author: ![ikakavas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ikakavas/32/34430_2.png) [@ikakavas](https://discuss.elastic.co/u/ikakavas)
#### Post date: [January 23, 2025, 5:52am UTC](https://discuss.elastic.co/t/kibana-7-17-23-8-15-0-security-updates-esa-2024-32-esa-2024-33/373548/1 "2025-01-23T05:52:11Z")

</div>

### Kibana allocation of resources without limits or throttling leads to crash (ESA-2024-33)

An allocation of resources without limits or throttling in Kibana can lead to a crash caused by a specially crafted request to `/api/metrics/snapshot`. This can be carried out by users with read access to the Observability Metrics or Logs features in Kibana.

### Affected Versions:

Kibana versions up to and including 7.17.22 and 8.0.0 up to and including 8.14.3

### Solutions and Mitigations:

The issue is resolved in versions 7.17.23 and 8.15.0

**Severity:** CVSSv3.1: 6.5 (Medium) - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

**CVE ID** : CVE-2024-52972

* * *
  

### Kibana allocation of resources without limits or throttling leads to crash (ESA-2024-32)

An allocation of resources without limits or throttling in Kibana can lead to a crash caused by a specially crafted payload to a number of inputs in Kibana UI. This can be carried out by users with read access to any feature in Kibana.

### Affected Versions:

Kibana versions up to and including 7.17.22 and 8.0.0 up to and including 8.14.3

### Solutions and Mitigations:

The issue is resolved in versions 7.17.23 and 8.15.0

**Severity:** CVSSv3.1: 6.5 (Medium) - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

**CVE ID** : CVE-2024-43708

* * *

2025-05-14: Wording updated in the "Affected Versions" section to improve the clarity around the affected versions.
