CVE-2017-8452
UnknownEPSS 1.38%
Last modified
CVE-2017-8452 is a vulnerability of currently unknown severity. Kibana versions prior to 5.2.1 configured for SSL client access, file descriptors will fail to be cleaned up after certain requests and will accumulate over time until the process crashes.. EPSS estimates a 1.38% chance of exploitation in the next 30 days.
Description
Kibana versions prior to 5.2.1 configured for SSL client access, file descriptors will fail to be cleaned up after certain requests and will accumulate over time until the process crashes.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Elastic | Kibana | <= 5.2.0 |
References
- https://www.elastic.co/community/securityVendor Advisory
- https://www.elastic.co/community/securityVendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2017-8452?
Kibana versions prior to 5.2.1 configured for SSL client access, file descriptors will fail to be cleaned up after certain requests and will accumulate over time until the process crashes.
How severe is CVE-2017-8452?
Severity scoring for CVE-2017-8452 is pending analysis. The EPSS model estimates a 1.38% probability of exploitation in the next 30 days.
How do I fix CVE-2017-8452?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2017
- CVE-2017-8446The Reporting feature in X-Pack in versions prior to 5.5.2 a…
- CVE-2017-8447An error was found in the X-Pack Security 5.3.0 to 5.5.2 pri…
- CVE-2017-8448An error was found in the permission model used by X-Pack Al…
- CVE-2017-8449X-Pack Security 5.2.x would allow access to more fields than…
- CVE-2017-8450X-Pack 5.1.1 did not properly apply document and field level…
- CVE-2017-8451With X-Pack installed, Kibana versions before 5.3.1 have an …
- CVE-2017-8453Foxit Reader before 8.2.1 and PhantomPDF before 8.2.1 have a…
- CVE-2017-8454Foxit Reader before 8.2.1 and PhantomPDF before 8.2.1 have a…
- CVE-2017-8455Foxit Reader before 8.2.1 and PhantomPDF before 8.2.1 have a…
- CVE-2017-8458Brave 0.12.4 has a URI Obfuscation issue in which a string s…
- CVE-2017-8459Brave 0.12.4 has a Status Bar Obfuscation issue in which a r…5.3
- CVE-2017-8460Windows PDF in Windows 8.1, Windows Server 2012 Gold and R2,…
Are you affected by CVE-2017-8452?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
