Home

Description

Unrestricted file upload in Kibana allows an authenticated attacker to compromise software integrity by uploading a crafted malicious file due to insufficient server-side validation.

PUBLISHED Reserved 2025-01-31 | Published 2025-05-01 | Updated 2025-05-06 | Assigner elastic




MEDIUM: 4.3CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N

Problem types

CWE-434 Unrestricted Upload of File with Dangerous Type

Product status

Default status
unaffected

7.17.0 (semver) before 7.17.18
affected

8.0.0 (semver) before 8.13.0
affected

References

discuss.elastic.co/...3-0-security-update-esa-2024-47/377711

cve.org (CVE-2025-25016)

nvd.nist.gov (CVE-2025-25016)

Download JSON