First published: Thu May 01 2025(Updated: )
Unrestricted file upload in Kibana allows an authenticated attacker to compromise software integrity by uploading a crafted malicious file due to insufficient server-side validation.
Credit: bressers@elastic.co
Affected Software | Affected Version | How to fix |
---|---|---|
Elastic |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-25016 has a high severity rating due to its potential for enabling unauthorized file uploads and compromising software integrity.
To fix CVE-2025-25016, update your Kibana installation to the latest version where the vulnerability is patched.
CVE-2025-25016 affects users of Elastic Kibana versions prior to the security update.
The impact of CVE-2025-25016 includes the potential for attackers to upload malicious files that could compromise the integrity of the Kibana software.
You can identify if your system is vulnerable to CVE-2025-25016 by checking if you are using a susceptible version of Elastic Kibana.