Kibana 8.15.x < 8.17.3 (ESA_2025_06)

high Nessus Plugin ID 232287

Synopsis

The remote host is missing a security update.

Description

The version of Kibana installed on the remote host is prior to 8.17.3. It is, therefore, affected by a vulnerability as referenced in the ESA_2025_06 advisory.

- Prototype pollution in Kibana leads to arbitrary code execution via a crafted file upload and specifically crafted HTTP requests. In Kibana versions >= 8.15.0 and < 8.17.1, this is exploitable by users with the Viewer role. In Kibana versions 8.17.1 and 8.17.2 , this is only exploitable by users that have roles that contain all the following privileges: fleet-all, integrations-all, actions:execute-advanced-connectors (CVE-2025-25012)

Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.

Solution

Upgrade to Kibana version 8.17.3 or later.

See Also

http://www.nessus.org/u?53693415

Plugin Details

Severity: High

ID: 232287

File Name: kibana_esa_2025_06.nasl

Version: 1.1

Type: remote

Family: CGI abuses

Published: 3/7/2025

Updated: 3/7/2025

Supported Sensors: Nessus

Risk Information

VPR

Risk Factor: Critical

Score: 9.0

Vulnerability Information

CPE: cpe:/a:elasticsearch:kibana

Required KB Items: installed_sw/Kibana

Exploit Ease: No known exploits are available

Patch Publication Date: 3/6/2025

Vulnerability Publication Date: 3/6/2025

Reference Information

CVE: CVE-2025-25012

IAVB: 2025-B-0035