Description


Improper Validation of Array Index (CWE-129) exists in Metricbeat can allow an attacker to cause a Denial of Service through Input Data Manipulation (CAPEC-153) via specially crafted, malformed payloads sent to the Graphite server metricset or Zookeeper server metricset. Additionally, Improper Input Validation (CWE-20) exists in the Prometheus helper module that can allow an attacker to cause a Denial of Service through Input Data Manipulation (CAPEC-153) via specially crafted, malformed metric data.

Related CPE's


a

elastic

kibana

4

Weaknesses



CWE-129

CVSS impact metrics


CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

6.5 · Medium

Information


Source identifier

[email protected]

Vulnerability status

Analyzed

Published

2026-01-13T21:15:50.647Z

1 month ago

Last modified

2026-01-22T19:57:29.927Z

4 weeks ago