SB2025100655 - Multiple vulnerabilities in Kibana
Published: October 6, 2025
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 3 secuirty vulnerabilities.
1) Insufficiently protected credentials (CVE-ID: CVE-2025-37728)
The vulnerability allows a remote user to gain access to sensitive information.
The vulnerability exists due to insufficient protection of credentials in the Crowdstrike connector. A remote user can access cached credentials from an Elastic Crowdstrike connector in another space by creating and running a Crowdstrike connector in a space to which they have access.
2) Stored cross-site scripting (CVE-ID: CVE-2025-25009)
The disclosed vulnerability allows a remote user to perform cross-site scripting (XSS) attacks.
The vulnerability exists due to insufficient sanitization of user-supplied data when performing case file upload. A remote user can inject and execute arbitrary HTML and script code in user's browser in context of vulnerable website.
3) Stored cross-site scripting (CVE-ID: CVE-2025-25018)
The disclosed vulnerability allows a remote user to perform cross-site scripting (XSS) attacks.
The vulnerability exists due to insufficient sanitization of user-supplied data. A remote user can inject and execute arbitrary HTML and script code in user's browser in context of vulnerable website.
Remediation
Install update from vendor's website.
References
- https://discuss.elastic.co/t/kibana-crowdstrike-connector-8-18-8-8-19-5-9-0-8-and-9-1-5-security-update-esa-2025-19/382455
- https://discuss.elastic.co/t/kibana-8-18-8-8-19-5-9-0-8-and-9-1-5-security-update-esa-2025-20/382449
- https://discuss.elastic.co/t/kibana-8-18-8-8-19-5-9-0-8-9-1-5-security-update-esa-2025-17/382451