A flaw was discovered in Kibana in which users with Read access to the Uptime feature could modify alerting rules. A user with this privilege would be able to create new alerting rules or overwrite existing ones. However, any new or modified rules would not be enabled, and a user with this privilege could not modify alerting connectors. This effectively means that Read users could disable existing alerting rules.
Weaknesses in this category are related to the management of permissions, privileges, and other security features that are used to perform access control.
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
Link | Tags |
---|---|
https://discuss.elastic.co/t/elastic-stack-7-17-1-security-update/298447 | vendor advisory |