Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2025-25018

Опубликовано: 10 окт. 2025
Источник: redhat
CVSS3: 8.7
EPSS Низкий

Описание

Improper Neutralization of Input During Web Page Generation in Kibana can lead to stored Cross-Site Scripting (XSS)

A stored Cross-Site Scripting (XSS) vulnerability in Kibana, caused by improper neutralization of user input during web page generation. This flaw allows a low-privileged attacker to inject malicious scripts into Kibana dashboards or visualizations, which execute in other users’ browsers and can lead to data theft or session compromise.

Отчет

This vulnerability is considered Important rather than Moderate because it enables persistent client-side code execution within a shared analytics environment. Unlike reflected or transient XSS flaws, the injected payload in CVE-2025-25018 is stored on the Kibana server and automatically executed whenever affected dashboards or visualizations are viewed by other authenticated users. This persistence increases both impact and reach, allowing lateral compromise across user sessions and potential exfiltration of sensitive data from Elasticsearch queries or credentials stored in the browser.

Меры по смягчению последствий

Mitigation is either unavailable or does not meet Red Hat Product Security standards for usability, deployment, applicability, or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Logging Subsystem for Red Hat OpenShiftopenshift-logging/cluster-logging-rhel9-operatorNot affected
Logging Subsystem for Red Hat OpenShiftopenshift-logging/elasticsearch-rhel9-operatorNot affected
Logging Subsystem for Red Hat OpenShiftopenshift-logging/kibana6-rhel8Not affected
Red Hat JBoss Enterprise Application Platform 8kibanaNot affected
Red Hat OpenShift distributed tracing 3rhosdt/tempo-jaeger-query-rhel8Affected
Red Hat OpenStack Platform 16.2puppet-kibana3Not affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-79
https://bugzilla.redhat.com/show_bug.cgi?id=2403039Kibana: Kibana Stored Cross-Site Scripting (XSS)

EPSS

Процентиль: 12%
0.00214
Низкий

8.7 High

CVSS3

Связанные уязвимости

CVSS3: 8.7
nvd
10 месяцев назад

Improper Neutralization of Input During Web Page Generation in Kibana can lead to stored Cross-Site Scripting (XSS)

CVSS3: 8.7
debian
10 месяцев назад

Improper Neutralization of Input During Web Page Generation in Kibana ...

CVSS3: 8.7
github
10 месяцев назад

Improper Neutralization of Input During Web Page Generation in Kibana can lead to stored Cross-Site Scripting (XSS)

EPSS

Процентиль: 12%
0.00214
Низкий

8.7 High

CVSS3