First published: Tue May 06 2025(Updated: )
A Prototype pollution vulnerability in Kibana leads to arbitrary code execution via crafted HTTP requests to machine learning and reporting endpoints.
Credit: bressers@elastic.co
Affected Software | Affected Version | How to fix |
---|---|---|
Elastic |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-25014 is a critical severity vulnerability that allows arbitrary code execution.
To mitigate CVE-2025-25014, you should upgrade to the latest patched version of Kibana as recommended by Elastic.
CVE-2025-25014 impacts multiple versions of Kibana including versions prior to the latest security updates.
Users of Kibana are at risk of unauthorized access and execution of arbitrary code due to this vulnerability.
In addition to upgrading, ensure your Kibana instance is behind a firewall and monitor for suspicious activity.