5.4
/ 10
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Description
Insufficiently Protected Credentials in the Crowdstrike connector can lead to Crowdstrike credentials being leaked. A malicious user can access cached credentials from a Crowdstrike connector in another space by creating and running a Crowdstrike connector in a space to which they have access.
Basic Information
ID
CVE-2025-37728
Source
elastic
Published
Oct 7, 2025 at 13:54
Affected Product
Vendor
Elastic
Product
Kibana
Version
7.0.0
Affected Versions
Elastic Kibana 7.0.0
Elastic Kibana 8.14.0
Elastic Kibana 8.19.0
Elastic Kibana 9.0.0
Elastic Kibana 9.1.0
Elastic Kibana 8.14.0
Elastic Kibana 8.19.0
Elastic Kibana 9.0.0
Elastic Kibana 9.1.0