CVE-2025-25012 Details
Description
URL redirection to an untrusted site ('Open Redirect') in Kibana can lead to sending a user to an arbitrary site and server-side request forgery via a specially crafted URL.
A URL redirection vulnerability, known as 'Open Redirect', has been identified in Elastic Kibana. This issue allows for redirection to an untrusted site, potentially leading to server-side request forgery (SSRF) by using a specially crafted URL. The vulnerability affects Kibana versions through 7.17.28, 8.0.0 through 8.17.7, 8.18.0 through 8.18.2, and 9.0.0 through 9.0.2. It is present in Kibana installations that utilize Short URLs within the Discover, Dashboard, and Visualization Library features.
Users can upgrade to Kibana versions 7.17.29, 8.17.8, 8.18.3, or 9.0.3. For those unable to upgrade, self-hosted installations with a Basic license should restrict access to Kibana features that allow Short URL creation. Cloud users can also limit access to these features.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jun 25, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://discuss.elastic.co/t/kibana-7-17-29-8-17-8-8-18-3-9-0-3-security-update-esa-2025-10/379444 | [email protected] | Issue TrackingPatchVendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-601 | URL Redirection to Untrusted Site ('Open Redirect') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| elastic kibana | >= 7.0.0, < 7.17.29 >= 8.0.0, < 8.17.8 >= 8.18.0, < 8.18.3 >= 9.0.0, < 9.0.3 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Sep 30, 2025 | Initial Analysis | [email protected] |
| Jun 25, 2025 | New CVE Received | [email protected] |