Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2025-37732

Опубликовано: 15 дек. 2025
Источник: redhat
CVSS3: 5.4
EPSS Низкий

Описание

Improper neutralization of input during web page generation ('Cross-site Scripting') (CWE-79) allows an authenticated user to render HTML tags within a user’s browser via the integration package upload functionality. This issue is related to ESA-2025-17 (CVE-2025-25018) bypassing that fix to achieve HTML injection.

A flaw was found in Kibana. This vulnerability allows an authenticated user to render HTML tags within a user’s browser via the integration package upload functionality.

Отчет

This vulnerability is rated Moderate for Red Hat products as it affects Kibana in OpenShift Container Platform. An authenticated user can exploit this cross-site scripting flaw by uploading a malicious integration package, leading to the rendering of arbitrary HTML tags within a user's browser.

Меры по смягчению последствий

Restrict network access to the Kibana instance to only trusted users and networks. Implement firewall rules to limit inbound connections to the Kibana service to only necessary sources. This reduces the attack surface by ensuring only authorized personnel can access the integration package upload functionality. A restart or service reload may be required for firewall changes to take full effect.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Logging Subsystem for Red Hat OpenShiftopenshift-logging/kibana6-rhel8Fix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-79
https://bugzilla.redhat.com/show_bug.cgi?id=2422246kibana: Kibana: Cross-site Scripting (XSS) via integration package upload

EPSS

Процентиль: 8%
0.00177
Низкий

5.4 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.4
nvd
8 месяцев назад

Improper neutralization of input during web page generation ('Cross-site Scripting') (CWE-79) allows an authenticated user to render HTML tags within a user’s browser via the integration package upload functionality. This issue is related to ESA-2025-17 (CVE-2025-25018) bypassing that fix to achieve HTML injection.

CVSS3: 5.4
debian
8 месяцев назад

Improper neutralization of input during web page generation ('Cross-si ...

CVSS3: 5.4
redos
6 месяцев назад

Уязвимость kibana

CVSS3: 5.4
github
8 месяцев назад

Improper neutralization of input during web page generation ('Cross-site Scripting') (CWE-79) allows an authenticated user to render HTML tags within a user’s browser via the integration package upload functionality. This issue is related to ESA-2025-17 (CVE-2025-25018) bypassing that fix to achieve HTML injection.

EPSS

Процентиль: 8%
0.00177
Низкий

5.4 Medium

CVSS3