CVE-2025-37728: Kibana Insufficiently Protected Credentials in the CrowdStrike Connector
Insufficiently Protected Credentials in the Crowdstrike connector can lead to Crowdstrike credentials being leaked. A malicious user can access cached credentials from a Crowdstrike connector in another space by creating and running a Crowdstrike connector in a space to which they have access.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-37728?
CVE-2025-37728 is classified as a high severity vulnerability due to the potential for credential leakage.
How do I fix CVE-2025-37728?
To remediate CVE-2025-37728, ensure that proper credential protection measures are implemented and review your Crowdstrike connector configurations.
What software is affected by CVE-2025-37728?
CVE-2025-37728 affects the CrowdStrike Crowdstrike Connector and Elastic Kibana.
What are the potential impacts of CVE-2025-37728?
The potential impact of CVE-2025-37728 includes unauthorized access to sensitive Crowdstrike credentials.
Is there a patch available for CVE-2025-37728?
Yes, patches and updates to address CVE-2025-37728 should be obtained from Crowdstrike and Elastic.