CVE-2020-7016 - log back

CVE-2020-7016 edited at 29 Jul 2020 20:53:11
Severity
- Unknown
+ Medium
Remote
- Unknown
+ Remote
Type
- Unknown
+ Denial of service
Description
+ Kibana versions before 6.8.11 and 7.8.1 contain a denial of service (DoS) flaw in Timelion. An attacker can construct a URL that when viewed by a Kibana user can lead to the Kibana process consuming large amounts of CPU and becoming unresponsive.
References
+ https://discuss.elastic.co/t/elastic-stack-6-8-11-and-7-8-1-security-update/242786
Notes
CVE-2020-7016 created at 29 Jul 2020 20:52:47