VDB

WID-SEC-W-2025-2216

WID-SEC-W-2025-2216 PUBLISHED

Ein entfernter authentisierter oder anonymer Angreifer kann mehrere Schwachstellen in Kibana ausnutzen, um Cross-Site-Scripting-Angriffe zu starten oder vertrauliche Informationen offenzulegen.

Affected Products

VendorProductVersions
Open Source Kibana 9.1.4
Open Source Kibana 8.18.8
Open Source Kibana 8.19.5
Open Source Kibana 9.0.7
Open Source Kibana 9.1.5
Open Source Kibana <8.18.8
Open Source Kibana <9.0.8
Open Source Kibana <8.19.5
Open Source Kibana <9.0.7
Open Source Kibana <9.1.5
Open Source Kibana 8.19.4
Open Source Kibana <8.19.4
Open Source Kibana 9.0.8
Open Source Kibana <9.1.4

Timeline

  • Oct 6, 2025 CVE Published
  • Oct 8, 2025 CVE Updated
Open in Interactive Console →
$ Console Community · 100/wk Open console ›