Vulnerability Description
URL redirection to an untrusted site ('Open Redirect') in Kibana can lead to sending a user to an arbitrary site and server-side request forgery via a specially crafted URL.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Elastic | Kibana | >= 7.0.0, < 7.17.29 |
Related Weaknesses (CWE)
References
- https://discuss.elastic.co/t/kibana-7-17-29-8-17-8-8-18-3-9-0-3-security-update-Issue TrackingPatchVendor Advisory
FAQ
What is CVE-2025-25012?
CVE-2025-25012 is a vulnerability with a CVSS score of 4.3 (MEDIUM). URL redirection to an untrusted site ('Open Redirect') in Kibana can lead to sending a user to an arbitrary site and server-side request forgery via a specially crafted URL.
How severe is CVE-2025-25012?
CVE-2025-25012 has been rated MEDIUM with a CVSS base score of 4.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-25012?
Check the references section above for vendor advisories and patch information. Affected products include: Elastic Kibana.