CVE-2025-25015

P

rototype pollution in Kibana leads to arbitrary code execution via a crafted file upload and specifically crafted HTTP requests. In Kibana versions >= 8.15.0 and < 8.17.1, this is exploitable by users with the Viewer role. In Kibana versions 8.17.1 and 8.17.2 , this is only exploitable by users that have roles that contain all the following privileges: fleet-all, integrations-all, actions:execute-advanced-connectors

Configurations

Configuration 1 (hide)

OR cpe:2.3:a:elastic:kibana:*:*:*:*:*:*:*:*
cpe:2.3:a:elastic:kibana:*:*:*:*:*:*:*:*

History

02 Oct 2025, 17:53

Type Values Removed Values Added
First Time Elastic
Elastic kibana
CPE cpe:2.3:a:elastic:kibana:*:*:*:*:*:*:*:*
References () https://discuss.elastic.co/t/kibana-8-17-3-8-16-6-security-update-esa-2025-06/375441 - () https://discuss.elastic.co/t/kibana-8-17-3-8-16-6-security-update-esa-2025-06/375441 - Mitigation, Vendor Advisory

02 Apr 2025, 17:15

Type Values Removed Values Added
References
  • {'url': 'https://discuss.elastic.co/t/kibana-8-17-3-security-update-esa-2025-06/375441', 'source': '[email protected]'}
  • () https://discuss.elastic.co/t/kibana-8-17-3-8-16-6-security-update-esa-2025-06/375441 -

05 Mar 2025, 10:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-03-05 10:15

Updated : 2025-10-02 17:53


NVD link : CVE-2025-25015

Mitre link : CVE-2025-25015

CVE.ORG link : CVE-2025-25015


JSON object : View

Products Affected
CWE
CWE-1321

Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')