Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2025-25017

Опубликовано: 10 окт. 2025
Источник: redhat
CVSS3: 8.2
EPSS Низкий

Описание

Improper Neutralization of Input During Web Page Generation in Kibana can lead to Cross-Site Scripting (XSS)

A Cross-Site Scripting (XSS) vulnerability in Kibana’s Vega visualization engine. It results from improper input validation in Vega visualization specifications, allowing attackers to inject malicious JavaScript. Successful exploitation could lead to session hijacking, data theft, or privilege escalation within Kibana dashboards.

Отчет

This vulnerability is rated Important rather than Moderate because it allows unauthenticated remote exploitation through user interaction, enabling attackers to execute arbitrary JavaScript within the Kibana interface and compromise the confidentiality and integrity of dashboard data. Unlike moderate XSS issues confined to low-impact contexts, this flaw occurs in the Vega visualization engine, which operates within privileged browser sessions connected to sensitive Elastic data. The cross-context nature (S:C) and high integrity impact (I:H) in the CVSS vector indicate that an attacker can potentially elevate privileges, steal session tokens, or alter visualization outputs, posing a significant risk to operational security and data trust within the Kibana environment.

Меры по смягчению последствий

Mitigation is either unavailable or does not meet Red Hat Product Security standards for usability, deployment, applicability, or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Logging Subsystem for Red Hat OpenShiftopenshift-logging/cluster-logging-rhel9-operatorNot affected
Logging Subsystem for Red Hat OpenShiftopenshift-logging/elasticsearch-rhel8-operatorNot affected
Logging Subsystem for Red Hat OpenShiftopenshift-logging/elasticsearch-rhel9-operatorNot affected
Logging Subsystem for Red Hat OpenShiftopenshift-logging/kibana6-rhel8Not affected
Red Hat JBoss Enterprise Application Platform 8kibanaNot affected
Red Hat JBoss Enterprise Application Platform 8org.elasticsearch.plugin/kibanaNot affected
Red Hat OpenShift distributed tracing 3rhosdt/tempo-jaeger-query-rhel8Affected
Red Hat OpenStack Platform 16.2puppet-kibana3Not affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-79
https://bugzilla.redhat.com/show_bug.cgi?id=2403040Kibana: Kibana Stored Cross-Site Scripting (XSS)

EPSS

Процентиль: 17%
0.00256
Низкий

8.2 High

CVSS3

Связанные уязвимости

CVSS3: 8.2
nvd
11 месяцев назад

Improper Neutralization of Input During Web Page Generation in Kibana can lead to Cross-Site Scripting (XSS)

CVSS3: 8.2
debian
11 месяцев назад

Improper Neutralization of Input During Web Page Generation in Kibana ...

CVSS3: 8.2
github
11 месяцев назад

Improper Neutralization of Input During Web Page Generation in Kibana can lead to Cross-Site Scripting (XSS)

EPSS

Процентиль: 17%
0.00256
Низкий

8.2 High

CVSS3