The Elastic team has published two critical vulnerabilities, identified as CVE-2024-37288 and CVE-2024-37285, with CVSS scores of 9.9 and 9.3 respectively, affecting Kibana versions 8.15.1 and earlier. Both vulnerabilities allow for remote code execution (RCE).
To resolve these vulnerabilities, it is recommended to update to version 8.15.1, which can be found at the following link: Kibana 8.15.1 Security Update.