Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Multiple Kibana Vulnerabilities Enables SSRF and XSS Attacks

Multiple Kibana Vulnerabilities Enables SSRF and XSS Attacks

Posted on November 13, 2025November 13, 2025 By CWS

Elastic Safety has disclosed important vulnerabilities affecting Kibana that might allow attackers to execute Server-Facet Request Forgery (SSRF) and Cross-Web site Scripting (XSS) assaults towards susceptible deployments.

The vulnerabilities stem from insufficient origin validation within the Observability AI Assistant part.

The first vulnerability, tracked as CVE-2025-37734 beneath Elastic Safety Advisory ESA-2025-24, includes an origin validation error in Kibana.

This flaw permits attackers to forge Origin HTTP headers, bypassing safety controls designed to forestall unauthorized requests from exterior sources.

By exploiting this weak point, malicious actors can craft requests that trick Kibana into sending requests to unintended locations or executing unintended actions.

FieldDetailsCVE IDCVE-2025-37734Vulnerability TypeOrigin Validation Error (SSRF)CVSS Score4.3 (Medium)Assault VectorNetworkAffected Versions8.12.0-8.19.6, 9.1.0-9.1.6, 9.2.0Patch Versions8.19.7, 9.1.7, 9.2.1

The SSRF vulnerability allows attackers to entry inside community sources or providers that ought to stay remoted from exterior entry.

This will result in info disclosure, lateral motion inside networks, or additional exploitation of backend techniques.

The vulnerability impacts a number of Kibana variations, making it a widespread concern for organizations operating affected deployments.

Elastic researchers report that the vulnerability solely impacts deployments actively utilizing the Observability AI Assistant characteristic. The vulnerability impacts: Kibana 8.12.0 via 8.19.6, Kibana 9.1.0 via 9.1.6, and Kibana 9.2.0.

Organizations with out this part enabled are usually not affected by this flaw, which has a medium severity ranking (CVSS v3.1 rating of 4.3).

Whereas this will appear average, the affect shouldn’t be underestimated given the potential for unauthorized inside community entry and knowledge manipulation.

Elastic has launched patched variations addressing this vulnerability. Organizations ought to instantly improve to: Kibana 8.19.7, Kibana 9.1.7, and Kibana 9.2.1.

Elastic Cloud Serverless prospects are already protected, as steady deployment and patching fashions remediated this vulnerability earlier than public disclosure.

Organizations unable to improve instantly ought to think about turning off the Observability AI Assistant characteristic till patches will be utilized.

Moreover, implementing community segmentation and entry controls may also help restrict the potential affect of SSRF exploitation.

Comply with us on Google Information, LinkedIn, and X for every day cybersecurity updates. Contact us to characteristic your tales.

Cyber Security News Tags:Attacks, Enables, Kibana, Multiple, SSRF, Vulnerabilities, XSS

Post navigation

Previous Post: NHS Investigating Oracle EBS Hack Claims as Hackers Name Over 40 Alleged Victims
Next Post: Fake Chrome Extension “Safery” Steals Ethereum Wallet Seed Phrases Using Sui Blockchain

Related Posts

What Are The Takeaways from The Scattered Lapsus $Hunters Statement? What Are The Takeaways from The Scattered Lapsus $Hunters Statement? Cyber Security News
CrackArmor Flaws Expose Millions of Linux Servers to Risks CrackArmor Flaws Expose Millions of Linux Servers to Risks Cyber Security News
Kimwolf Android Botnet Hijacked 1.8 Million Android Devices Worldwide Kimwolf Android Botnet Hijacked 1.8 Million Android Devices Worldwide Cyber Security News
GitHub Copilot RCE Vulnerability via Prompt Injection Leads to Full System Compromise GitHub Copilot RCE Vulnerability via Prompt Injection Leads to Full System Compromise Cyber Security News
Hive0156 Hackers Attacking Government and Military Organizations to Deploy Remcos RAT Hive0156 Hackers Attacking Government and Military Organizations to Deploy Remcos RAT Cyber Security News
Open-Source Firewall IPFire 2.29 With New Reporting For Intrusion Prevention System Open-Source Firewall IPFire 2.29 With New Reporting For Intrusion Prevention System Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Huskeys Secures $8 Million in Seed Funding for ESM Platform
  • Critical XSS Flaw in Jira Could Compromise Organizations
  • Russian Group Star Blizzard Utilizes DarkSword iOS Exploit
  • Secrets Sprawl Expands in 2026: Key Insights for CISOs
  • Urgent Patches Address Critical Grafana Security Flaws

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Huskeys Secures $8 Million in Seed Funding for ESM Platform
  • Critical XSS Flaw in Jira Could Compromise Organizations
  • Russian Group Star Blizzard Utilizes DarkSword iOS Exploit
  • Secrets Sprawl Expands in 2026: Key Insights for CISOs
  • Urgent Patches Address Critical Grafana Security Flaws

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark