# Kibana 8.14.0/7.17.22 Security Update (ESA-2024-11)

**URL:** <https://discuss.elastic.co/t/kibana-8-14-0-7-17-22-security-update-esa-2024-11/361460>\
**Category:** Security Announcements\
**Created:** [June 14, 2024, 4:47am UTC](https://discuss.elastic.co/t/kibana-8-14-0-7-17-22-security-update-esa-2024-11/361460 "2024-06-14T04:47:49Z")\
**Posts on this page:** 1\
**Showing post:** 1

<div class="post-metadata">

**Author:** ![ikakavas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ikakavas/32/34430_2.png) [@ikakavas](https://discuss.elastic.co/u/ikakavas)\
**Post date:** [June 14, 2024, 4:47am UTC](https://discuss.elastic.co/t/kibana-8-14-0-7-17-22-security-update-esa-2024-11/361460/1 "2024-06-14T04:47:49Z")

</div>

## Kibana uncontrolled resource consumption (ESA-2024-11)

A high-privileged user, allowed to create [custom osquery packs](https://www.elastic.co/guide/en/kibana/current/osquery.html#osquery-schedule-query) could affect the availability of Kibana by uploading a maliciously crafted osquery pack.

### Affected Versions:

Kibana versions after 7.13.0 and before 7.17.22 and versions after 8.0.0 and before 8.14.0

### Solutions and Mitigations:

The issue is resolved in version 7.17.22 and 8.14.0

**Severity** : CVSSv3.1: 4.9(Medium) - [CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H](https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H)

**CVE ID:** CVE-2024-23443

### Updates

**2025-03-19** : Clarify affected 7.x versions.

---

_[View the full topic](https://discuss.elastic.co/t/kibana-8-14-0-7-17-22-security-update-esa-2024-11/361460)._
