VDB
WID-SEC-W-2025-2216
WID-SEC-W-2025-2216
PUBLISHED
Ein entfernter authentisierter oder anonymer Angreifer kann mehrere Schwachstellen in Kibana ausnutzen, um Cross-Site-Scripting-Angriffe zu starten oder vertrauliche Informationen offenzulegen.
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Open Source Kibana 9.1.4 | ||
| Open Source Kibana 8.18.8 | ||
| Open Source Kibana 8.19.5 | ||
| Open Source Kibana 9.0.7 | ||
| Open Source Kibana 9.1.5 | ||
| Open Source Kibana <8.18.8 | ||
| Open Source Kibana <9.0.8 | ||
| Open Source Kibana <8.19.5 | ||
| Open Source Kibana <9.0.7 | ||
| Open Source Kibana <9.1.5 | ||
| Open Source Kibana 8.19.4 | ||
| Open Source Kibana <8.19.4 | ||
| Open Source Kibana 9.0.8 | ||
| Open Source Kibana <9.1.4 |
Exploit Intelligence
- https://wid.cert-bund.de/.well-known/csaf/white/2025/wid-sec-w-2025-2216.json (circl)
- https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2025-2216 (circl)
- https://discuss.elastic.co/t/kibana-8-18-8-8-19-5-9-0-8-and-9-1-5-security-update-esa-2025-15/382449 (circl)
- https://discuss.elastic.co/t/kibana-8-18-8-8-19-4-9-0-7-9-1-4-security-update-esa-2025-16/382450 (circl)
- https://discuss.elastic.co/t/kibana-8-18-8-8-19-5-9-0-8-9-1-5-security-update-esa-2025-17/382451 (circl)
- https://discuss.elastic.co/t/kibana-crowdstrike-connector-8-18-8-8-19-5-9-0-8-and-9-1-5-security-update-esa-2025-19/382455 (circl)
- https://discuss.elastic.co/t/kibana-8-18-8-8-19-5-9-0-8-and-9-1-5-security-update-esa-2025-20/382449 (circl)
Timeline
- Oct 6, 2025 CVE Published
- Oct 8, 2025 CVE Updated
References
- https://wid.cert-bund.de/.well-known/csaf/white/2025/wid-sec-w-2025-2216.json advisory
- https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2025-2216 advisory
- https://discuss.elastic.co/t/kibana-8-18-8-8-19-5-9-0-8-and-9-1-5-security-update-esa-2025-15/382449 url
- https://discuss.elastic.co/t/kibana-8-18-8-8-19-4-9-0-7-9-1-4-security-update-esa-2025-16/382450 url
- https://discuss.elastic.co/t/kibana-8-18-8-8-19-5-9-0-8-9-1-5-security-update-esa-2025-17/382451 url
- https://discuss.elastic.co/t/kibana-crowdstrike-connector-8-18-8-8-19-5-9-0-8-and-9-1-5-security-update-esa-2025-19/382455 url
- https://discuss.elastic.co/t/kibana-8-18-8-8-19-5-9-0-8-and-9-1-5-security-update-esa-2025-20/382449 url