¡¾Îó²îͨ¸æ¡¿Kibana ÔÐÍÎÛȾµ¼ÖÂí§Òâ´úÂëÖ´ÐÐÎó²î (CVE-2025-25014)
Ðû²¼Ê±¼ä 2025-05-07Ò»¡¢Îó²î¸ÅÊö
Îó²îÃû³Æ | Kibana ÔÐÍÎÛȾµ¼ÖÂí§Òâ´úÂëÖ´ÐÐÎó²î | ||
CVE ID | CVE-2025-25014 | ||
Îó²îÀàÐÍ | ÔÐÍÎÛȾ | ·¢Ã÷ʱ¼ä | 2025-05-07 |
Îó²îÆÀ·Ö | 9.1 | Îó²îÆ·¼¶ | ÑÏÖØ |
¹¥»÷ÏòÁ¿ | ÍøÂç | ËùÐèȨÏÞ | ¸ß |
ʹÓÃÄÑ¶È | µÍ | Óû§½»»¥ | ²»ÐèÒª |
PoC/EXP | δ¹ûÕæ | ÔÚҰʹÓà | δ·¢Ã÷ |
Elastic KibanaÊÇÒ»¸ö¿ªÔ´Êý¾Ý¿ÉÊÓ»¯ºÍÆÊÎöƽ̨£¬£¬×¨ÎªÓëElasticsearchÅäºÏʹÓöøÉè¼Æ¡£¡£¡£ËüÔÊÐíÓû§Í¨¹ýͼÐνçÃæÖ±¹ÛµØÕ¹Ê¾ºÍ̽Ë÷Êý¾Ý£¬£¬Ö§³ÖʵʱÊý¾ÝÆÊÎö¡¢ÈÕÖ¾¼à¿ØºÍÓªÒµÖ¸±ê¸ú×Ù¡£¡£¡£KibanaÌṩǿʢµÄËÑË÷¡¢¹ýÂ˺ͿÉÊÓ»¯¹¦Ð§£¬£¬ÊÊÓÃÓÚ´ó¹æÄ£Êý¾Ý´¦Öóͷ£ºÍչʾ¡£¡£¡£Ëü³£ÓÃÓÚÇå¾²ÊÂÎñ¼à¿Ø¡¢ÈÕÖ¾ÆÊÎö¡¢ÓªÒµÖÇÄܵÈÁìÓò£¬£¬ÊÇElastic Stack£¨°üÀ¨Elasticsearch¡¢LogstashºÍBeats£©µÄ½¹µã×é¼þÖ®Ò»¡£¡£¡£
2025Äê5ÔÂ7ÈÕ£¬£¬bevictorΰµÂ¼¯ÍÅVSRC¼à²âµ½Elastic¹Ù·½Ðû²¼µÄÇ徲ͨ¸æ£¬£¬Ö¸³öElastic Kibana±£´æÔÐÍÎÛȾÎó²î¡£¡£¡£¹¥»÷Õß¿Éͨ¹ýÈ«ÐĽṹµÄHTTPÇëÇ󣬣¬Ê¹ÓÃKibanaµÄ»úеѧϰºÍ±¨¸æ¶Ëµã£¬£¬¿ÉÄܵ¼ÖÂí§Òâ´úÂëÖ´ÐУ¬£¬Îó²î¼¶±ðÑÏÖØ£¬£¬Îó²îÆÀ·Ö9.1·Ö¡£¡£¡£
¶þ¡¢Ó°Ïì¹æÄ£
8.3.0 <= Kibana <= 8.17.5
Èý¡¢Çå¾²²½·¥
3.1 Éý¼¶°æ±¾
¹Ù·½ÒÑÐû²¼Çå¾²¸üУ¬£¬½¨ÒéÊÜÓ°ÏìÓû§¾¡¿ìÉý¼¶ÖÁ8.17.6¡¢8.18.1»ò9.0.1°æ±¾¡£¡£¡£
ÏÂÔØÁ´½Ó£ºhttps://github.com/elastic/kibana/releases
3.2 ÔÝʱ²½·¥
¹ØÓÚÎÞ·¨Éý¼¶µÄÓû§£¬£¬¿ÉÒÔͨ¹ý½ûÓûúеѧϰ»ò±¨¸æ¹¦Ð§À´»º½âΣº¦¡£¡£¡£×ÔÍйܺÍElastic Cloud°²ÅŵÄÓû§¿ÉÔÚkibana.ymlÎļþÖÐÌí¼Óxpack.ml.enabled: falseÀ´½ûÓûúеѧϰ¹¦Ð§£»£»£»£»£»£»Èô½öÐè½ûÓÃÒì³£¼ì²â¹¦Ð§£¬£¬×ÔÍйÜÓû§¿ÉÌí¼Óxpack.ml.ad.enabled: false¡£¡£¡£Í¬Ê±£¬£¬Óû§Ò²¿ÉÒÔͨ¹ýÔÚkibana.ymlÎļþÖÐÌí¼Óxpack.reporting.enabled: falseÀ´½ûÓñ¨¸æ¹¦Ð§¡£¡£¡£
3.3 ͨÓý¨Òé
? °´ÆÚ¸üÐÂϵͳ²¹¶¡£¬£¬ïÔÌϵͳÎó²î£¬£¬ÌáÉýЧÀÍÆ÷µÄÇå¾²ÐÔ¡£¡£¡£
3.4 ²Î¿¼Á´½Ó
https://discuss.elastic.co/t/kibana-8-17-6-8-18-1-or-9-0-1-security-update-esa-2025-07/377868