Bug 2402177 (CVE-2025-25009)

Summary: CVE-2025-25009 kibana: Kibana Cross-Site Scripting (XSS)
Product: [Other] Security Response Reporter: OSIDB Bzimport <bzimport>
Component: vulnerabilityAssignee: Product Security DevOps Team <prodsec-dev>
Status: NEW --- QA Contact:
Severity: high Docs Contact:
Priority: high    
Version: unspecifiedCC: jcantril, rojacob
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: ---
Doc Text:
A cross site scripting vulnerability has been discovered in the Kibana logging platform. For an attacker to exploit this vulnerability they must have permission to upload files to the platform.
Story Points: ---
Clone Of: Environment:
Last Closed: Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:

Description OSIDB Bzimport 2025-10-07 15:01:49 UTC
Improper Neutralization of Input During Web Page Generation in Kibana can lead to Stored XSS via case file upload.