Insufficiently Protected Credentials in Crowdstrike Connector by Crowdstrike
CVE-2025-37728
5.4MEDIUM
What is CVE-2025-37728?
A vulnerability in the Crowdstrike connector allows unauthorized access to sensitive credentials due to insufficient protection. An attacker could exploit this by creating a connector in an accessible space, gaining the ability to retrieve cached credentials from another instance of the connector. This flaw underscores the importance of robust credential management and security practices to prevent leakage of sensitive information.
Affected Version(s)
Kibana 7.0.0 <= 7.17.29
Kibana 8.14.0 <= 8.18.7
Kibana 8.19.0 <= 8.19.4