CVE-2025-25016: Kibana Unrestricted Upload of File
Unrestricted file upload in Kibana allows an authenticated attacker to compromise software integrity by uploading a crafted malicious file due to insufficient server-side validation.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2025-25016?
CVE-2025-25016 has a high severity rating due to its potential for enabling unauthorized file uploads and compromising software integrity.
How do I fix CVE-2025-25016?
To fix CVE-2025-25016, update your Kibana installation to the latest version where the vulnerability is patched.
Who is affected by CVE-2025-25016?
CVE-2025-25016 affects users of Elastic Kibana versions prior to the security update.
What is the impact of CVE-2025-25016?
The impact of CVE-2025-25016 includes the potential for attackers to upload malicious files that could compromise the integrity of the Kibana software.
How can I identify if my system is vulnerable to CVE-2025-25016?
You can identify if your system is vulnerable to CVE-2025-25016 by checking if you are using a susceptible version of Elastic Kibana.