Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2025-25012

Опубликовано: 25 июн. 2025
Источник: redhat
CVSS3: 4.3

Описание

URL redirection to an untrusted site ('Open Redirect') in Kibana can lead to sending a user to an arbitrary site and server-side request forgery via a specially crafted URL.

An open redirect flaw has been discovered in the Kibana interface. An attacker can craft a url which may redirect a user to an arbitrary third party site.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Logging Subsystem for Red Hat OpenShiftopenshift-logging/kibana6-rhel8Fix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-601

4.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 4.3
nvd
около 1 года назад

URL redirection to an untrusted site ('Open Redirect') in Kibana can lead to sending a user to an arbitrary site and server-side request forgery via a specially crafted URL.

CVSS3: 4.3
debian
около 1 года назад

URL redirection to an untrusted site ('Open Redirect') in Kibana can l ...

CVSS3: 4.3
github
около 1 года назад

URL redirection to an untrusted site ('Open Redirect') in Kibana can lead to sending a user to an arbitrary site and server-side request forgery via a specially crafted URL.

4.3 Medium

CVSS3