Unrestricted File Upload Vulnerability in Kibana by Elastic
CVE-2025-25016
4.3MEDIUM
What is CVE-2025-25016?
The unrestricted file upload vulnerability in Kibana enables authenticated attackers to upload malicious files due to inadequate server-side validation. This flaw poses a significant risk as it compromises the integrity of the software, allowing potential execution of arbitrary code or manipulation of the system. Users should promptly update to secure versions to mitigate this threat.
Affected Version(s)
Kibana 7.17.0 < 7.17.18
Kibana 8.0.0 < 8.13.0