Medium severity4.3NVD Advisory· Published May 1, 2025· Updated Jun 17, 2026
CVE-2025-25016
CVE-2025-25016
Description
Unrestricted file upload in Kibana allows an authenticated attacker to compromise software integrity by uploading a crafted malicious file due to insufficient server-side validation.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
5- osv-coords2 versions
>= 7.17.0, < 7.17.18+ 1 more
- (no CPE)range: >= 7.17.0, < 7.17.18
- (no CPE)range: >= 7.17.0, < 7.17.18
Patches
Vulnerability mechanics
References
1- discuss.elastic.co/t/kibana-7-17-19-and-8-13-0-security-update-esa-2024-47/377711nvdPatchVendor Advisory
News mentions
0No linked articles in our index yet.