Описание
Improper Neutralization of Input During Web Page Generation in Kibana can lead to stored Cross-Site Scripting (XSS)
A stored Cross-Site Scripting (XSS) vulnerability in Kibana, caused by improper neutralization of user input during web page generation. This flaw allows a low-privileged attacker to inject malicious scripts into Kibana dashboards or visualizations, which execute in other users’ browsers and can lead to data theft or session compromise.
Отчет
This vulnerability is considered Important rather than Moderate because it enables persistent client-side code execution within a shared analytics environment. Unlike reflected or transient XSS flaws, the injected payload in CVE-2025-25018 is stored on the Kibana server and automatically executed whenever affected dashboards or visualizations are viewed by other authenticated users. This persistence increases both impact and reach, allowing lateral compromise across user sessions and potential exfiltration of sensitive data from Elasticsearch queries or credentials stored in the browser.
Меры по смягчению последствий
Mitigation is either unavailable or does not meet Red Hat Product Security standards for usability, deployment, applicability, or stability.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Logging Subsystem for Red Hat OpenShift | openshift-logging/cluster-logging-rhel9-operator | Not affected | ||
| Logging Subsystem for Red Hat OpenShift | openshift-logging/elasticsearch-rhel9-operator | Not affected | ||
| Logging Subsystem for Red Hat OpenShift | openshift-logging/kibana6-rhel8 | Not affected | ||
| Red Hat JBoss Enterprise Application Platform 8 | kibana | Not affected | ||
| Red Hat OpenShift distributed tracing 3 | rhosdt/tempo-jaeger-query-rhel8 | Affected | ||
| Red Hat OpenStack Platform 16.2 | puppet-kibana3 | Not affected |
Показывать по
Дополнительная информация
Статус:
EPSS
8.7 High
CVSS3
Связанные уязвимости
Improper Neutralization of Input During Web Page Generation in Kibana can lead to stored Cross-Site Scripting (XSS)
Improper Neutralization of Input During Web Page Generation in Kibana ...
Improper Neutralization of Input During Web Page Generation in Kibana can lead to stored Cross-Site Scripting (XSS)
EPSS
8.7 High
CVSS3