Описание
Improper neutralization of input during web page generation ('Cross-site Scripting') (CWE-79) allows an authenticated user to render HTML tags within a user’s browser via the integration package upload functionality. This issue is related to ESA-2025-17 (CVE-2025-25018) bypassing that fix to achieve HTML injection.
A flaw was found in Kibana. This vulnerability allows an authenticated user to render HTML tags within a user’s browser via the integration package upload functionality.
Отчет
This vulnerability is rated Moderate for Red Hat products as it affects Kibana in OpenShift Container Platform. An authenticated user can exploit this cross-site scripting flaw by uploading a malicious integration package, leading to the rendering of arbitrary HTML tags within a user's browser.
Меры по смягчению последствий
Restrict network access to the Kibana instance to only trusted users and networks. Implement firewall rules to limit inbound connections to the Kibana service to only necessary sources. This reduces the attack surface by ensuring only authorized personnel can access the integration package upload functionality. A restart or service reload may be required for firewall changes to take full effect.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Logging Subsystem for Red Hat OpenShift | openshift-logging/kibana6-rhel8 | Fix deferred |
Показывать по
Дополнительная информация
Статус:
EPSS
5.4 Medium
CVSS3
Связанные уязвимости
Improper neutralization of input during web page generation ('Cross-site Scripting') (CWE-79) allows an authenticated user to render HTML tags within a user’s browser via the integration package upload functionality. This issue is related to ESA-2025-17 (CVE-2025-25018) bypassing that fix to achieve HTML injection.
Improper neutralization of input during web page generation ('Cross-si ...
Improper neutralization of input during web page generation ('Cross-site Scripting') (CWE-79) allows an authenticated user to render HTML tags within a user’s browser via the integration package upload functionality. This issue is related to ESA-2025-17 (CVE-2025-25018) bypassing that fix to achieve HTML injection.
EPSS
5.4 Medium
CVSS3