CVE-2024-43707
An issue was identified in Kibana where a user without access to Fleet can view Elastic Agent policies that could contain sensitive information. The nature of the sensitive information depends on the integrations enabled for the Elastic Agent and their respective versions.
- Affected products
- Kibana
- Elastic Kibana
- < 8.15.0
- Fix
- Available
- CVSS 3.1
- 7.7 HIGH
- EPSS
- 0.4% (34th percentile)
- Weakness
- CWE-200
- NVD status
- Analyzed
- Published
- 2025-01-23
CVE-2024-43707 at NVD
No indexed exploits for CVE-2024-43707 yet
Our index is partial: it proves presence, never absence
No exploit for CVE-2024-43707 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.