CVE-2025-25012: Elastic Kibana
Medium severity, CVSS 5.4. EPSS: 0.4% chance of exploitation in the next 30 days.
URL redirection to an untrusted site ('Open Redirect') in Kibana can lead to sending a user to an arbitrary site and server-side request forgery via a specially crafted URL.
Affected products
- Elastic Kibana: from 7.0.0, before 7.17.29 (fixed in 7.17.29); from 8.0.0, before 8.17.8 (fixed in 8.17.8); from 8.18.0, before 8.18.3 (fixed in 8.18.3); from 9.0.0, before 9.0.3 (fixed in 9.0.3)
Published 2025-06-25. Last modified 2026-06-17.