Elastic Fixes Multiple High-Severity Vulnerabilities in Kibana and Elasticsearch
ID: 21b73658-1686-5cab-979a-fdd72120554c
STIX ID: report--21b73658-1686-5cab-979a-fdd72120554c
Feed Name: securityonline.info
Elastic published advisories for five vulnerabilities in Kibana and Elasticsearch—three high-severity stored XSS flaws that can lead to data theft or session hijacking (notably CVE-2025-25009, CVE-2025-25017, CVE-2025-25018) and two information/credential disclosure issues in Elasticsearch audit logging and the CrowdStrike connector (CVE-2025-37727, CVE-2025-37728). Affected versions include Kibana ≤7.17.29 and up through 9.1.4; fixes are available in 8.18.8, 8.19.5, 9.0.8, and 9.1.5, with recommended mitigations for environments that cannot immediately upgrade.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
