Insufficiently Protected Credentials Affecting kibana package, versions <8.1.0>=8.14.0 <8.18.8>=8.19.0 <8.19.5>=9.0.0 <9.0.8>=9.1.0 <9.1.5


Severity

Recommended
0.0
medium
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.03% (6th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-JS-KIBANA-13706924
  • published27 Oct 2025
  • disclosed7 Oct 2025
  • creditUnknown

Introduced: 7 Oct 2025

NewCVE-2025-37728  (opens in a new tab)
CWE-522  (opens in a new tab)

How to fix?

Upgrade kibana to version 8.1.0, 8.18.8, 8.19.5, 9.0.8, 9.1.5 or higher.

Overview

kibana is an open source (Apache Licensed), browser-based analytics and search dashboard for Elasticsearch.

Affected versions of this package are vulnerable to Insufficiently Protected Credentials via the CrowdStrike connector. An attacker can obtain CrowdStrike credentials by accessing cached authentication data from a connector in another space by creating and executing a connector in a space to which they have access.

References

CVSS Base Scores

version 4.0
version 3.1