Close Menu
  • Home
  • AI
  • Big Data
  • Cloud Computing
  • iOS Development
  • IoT
  • IT/ Cybersecurity
  • Tech
    • Nanotechnology
    • Green Technology
    • Apple
    • Software Development
    • Software Engineering

Subscribe to Updates

Get the latest technology news from Bigteetechhub about IT, Cybersecurity and Big Data.

    What's Hot

    Building Outlook Add-ins from Idea to Launch: Outlook Add-in Development

    March 30, 2026

    Bringing AI to DevNet Learning Labs

    March 30, 2026

    What Do Termites Look Like? How to Spot the Signs in Your Home

    March 30, 2026
    Facebook X (Twitter) Instagram
    Facebook X (Twitter) Instagram
    Big Tee Tech Hub
    • Home
    • AI
    • Big Data
    • Cloud Computing
    • iOS Development
    • IoT
    • IT/ Cybersecurity
    • Tech
      • Nanotechnology
      • Green Technology
      • Apple
      • Software Development
      • Software Engineering
    Big Tee Tech Hub
    Home»IT/ Cybersecurity»Elastic Releases Urgent Fix for Critical Kibana Vulnerability Enabling Remote Code Execution
    IT/ Cybersecurity

    Elastic Releases Urgent Fix for Critical Kibana Vulnerability Enabling Remote Code Execution

    big tee tech hubBy big tee tech hubMarch 6, 20250512 Mins Read
    Share Facebook Twitter Pinterest Copy Link LinkedIn Tumblr Email Telegram WhatsApp
    Follow Us
    Google News Flipboard
    Elastic Releases Urgent Fix for Critical Kibana Vulnerability Enabling Remote Code Execution
    Share
    Facebook Twitter LinkedIn Pinterest Email Copy Link


    Mar 06, 2025Ravie LakshmananData Security / Software Security

    Elastic Releases Urgent Fix for Critical Kibana Vulnerability Enabling Remote Code Execution

    Elastic has rolled out security updates to address a critical security flaw impacting the Kibana data visualization dashboard software for Elasticsearch that could result in arbitrary code execution.

    The vulnerability, tracked as CVE-2025-25012, carries a CVSS score of 9.9 out of a maximum of 10.0. It has been described as a case of prototype pollution.

    “Prototype pollution in Kibana leads to arbitrary code execution via a crafted file upload and specifically crafted HTTP requests,” the company said in an advisory released Wednesday.

    Prototype pollution vulnerability is a security flaw that allows attackers to manipulate an application’s JavaScript objects and properties, potentially leading to unauthorized data access, privilege escalation, denial-of-service, or remote code execution.

    The vulnerability affects all versions of Kibana between 8.15.0 and 8.17.3. It has been addressed in version 8.17.3.

    Cybersecurity

    That said, in Kibana versions from 8.15.0 and prior to 8.17.1, the vulnerability is exploitable only by users with the Viewer role. In Kibana versions 8.17.1 and 8.17.2, it can only be exploited by users that have all the below-mentioned privileges –

    • fleet-all
    • integrations-all
    • actions:execute-advanced-connectors

    Users are advised to take steps to apply the latest fixes to safeguard against potential threats. In the event immediate patching is not an option, users are recommended to set the Integration Assistant feature flag to false (“xpack.integration_assistant.enabled: false”) in Kibana’s configuration (“kibana.yml”).

    In August 2024, Elastic addressed another critical prototype pollution flaw in Kibana (CVE-2024-37287, CVSS score: 9.9) that could lead to code execution. A month later, it resolved two severe deserialization bugs (CVE-2024-37288, CVSS score: 9.9 and CVE-2024-37285, CVSS score: 9.1) that could also permit arbitrary code execution.

    Found this article interesting? Follow us on Twitter  and LinkedIn to read more exclusive content we post.





    Source link

    Code Critical Elastic Enabling Execution Fix Kibana Releases Remote Urgent Vulnerability
    Follow on Google News Follow on Flipboard
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
    tonirufai
    big tee tech hub
    • Website

    Related Posts

    Three China-Linked Clusters Target Southeast Asian Government in 2025 Cyber Campaign

    March 30, 2026

    Microsoft Patch Tuesday, March 2026 Edition – Krebs on Security

    March 29, 2026

    How Silver Fox preys on Japanese firms this tax season

    March 28, 2026
    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    Building Outlook Add-ins from Idea to Launch: Outlook Add-in Development

    March 30, 2026

    Bringing AI to DevNet Learning Labs

    March 30, 2026

    What Do Termites Look Like? How to Spot the Signs in Your Home

    March 30, 2026

    Why Some Businesses Seem to Win Online Without Ever Feeling Like They Are Trying

    March 30, 2026
    About Us
    About Us

    Welcome To big tee tech hub. Big tee tech hub is a Professional seo tools Platform. Here we will provide you only interesting content, which you will like very much. We’re dedicated to providing you the best of seo tools, with a focus on dependability and tools. We’re working to turn our passion for seo tools into a booming online website. We hope you enjoy our seo tools as much as we enjoy offering them to you.

    Don't Miss!

    Building Outlook Add-ins from Idea to Launch: Outlook Add-in Development

    March 30, 2026

    Bringing AI to DevNet Learning Labs

    March 30, 2026

    Subscribe to Updates

    Get the latest technology news from Bigteetechhub about IT, Cybersecurity and Big Data.

      • About Us
      • Contact Us
      • Disclaimer
      • Privacy Policy
      • Terms and Conditions
      © 2026 bigteetechhub.All Right Reserved

      Type above and press Enter to search. Press Esc to cancel.