Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2025-37728

Опубликовано: 07 окт. 2025
Источник: redhat
CVSS3: 5.4
EPSS Низкий

Описание

Insufficiently Protected Credentials in the Crowdstrike connector can lead to Crowdstrike credentials being leaked. A malicious user can access cached credentials from a Crowdstrike connector in another space by creating and running a Crowdstrike connector in a space to which they have access.

A flaw was found in Kibana where the CrowdStrike connector stores credentials in a way that allows them to be accessed from other spaces. A malicious user could create and run a CrowdStrike connector in a space they control to access cached credentials belonging to another space, leading to unauthorized data access or manipulation.

Отчет

The impact is MODERATE because the exploitation requires a Kibana user with access to at least one space to trigger the attack. However, once exploited, the flaw exposes stored CrowdStrike API credentials that could be used to query or modify protected resources. The issue is fundamentally caused by insufficient credential isolation between spaces in the CrowdStrike connector.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Logging Subsystem for Red Hat OpenShiftopenshift-logging/kibana6-rhel8Fix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-522
https://bugzilla.redhat.com/show_bug.cgi?id=2402166kibana: Kibana Insufficiently Protected Credentials in the CrowdStrike Connector

EPSS

Процентиль: 14%
0.00232
Низкий

5.4 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.4
nvd
11 месяцев назад

Insufficiently Protected Credentials in the Crowdstrike connector can lead to Crowdstrike credentials being leaked. A malicious user can access cached credentials from a Crowdstrike connector in another space by creating and running a Crowdstrike connector in a space to which they have access.

CVSS3: 5.4
github
11 месяцев назад

Insufficiently Protected Credentials in the Crowdstrike connector can lead to Crowdstrike credentials being leaked. A malicious user can access cached credentials from a Crowdstrike connector in another space by creating and running a Crowdstrike connector in a space to which they have access.

EPSS

Процентиль: 14%
0.00232
Низкий

5.4 Medium

CVSS3