¡¾Îó²îͨ¸æ¡¿Kibana ÔÐÍÎÛȾµ¼ÖÂí§Òâ´úÂëÖ´ÐÐÎó²î (CVE-2025-25014)
Ðû²¼Ê±¼ä 2025-05-07Ò»¡¢Îó²î¸ÅÊö
Îó²îÃû³Æ | Kibana ÔÐÍÎÛȾµ¼ÖÂí§Òâ´úÂëÖ´ÐÐÎó²î | ||
CVE ID | CVE-2025-25014 | ||
Îó²îÀàÐÍ | ÔÐÍÎÛȾ | ·¢Ã÷ʱ¼ä | 2025-05-07 |
Îó²îÆÀ·Ö | 9.1 | Îó²îÆ·¼¶ | ÑÏÖØ |
¹¥»÷ÏòÁ¿ | ÍøÂç | ËùÐèȨÏÞ | ¸ß |
ʹÓÃÄÑ¶È | µÍ | Óû§½»»¥ | ²»ÐèÒª |
PoC/EXP | δ¹ûÕæ | ÔÚҰʹÓà | δ·¢Ã÷ |
Elastic KibanaÊÇÒ»¸ö¿ªÔ´Êý¾Ý¿ÉÊÓ»¯ºÍÆÊÎöƽ̨£¬×¨ÎªÓëElasticsearchÅäºÏʹÓöøÉè¼Æ¡£ËüÔÊÐíÓû§Í¨¹ýͼÐνçÃæÖ±¹ÛµØÕ¹Ê¾ºÍ̽Ë÷Êý¾Ý£¬Ö§³ÖʵʱÊý¾ÝÆÊÎö¡¢ÈÕÖ¾¼à¿ØºÍÓªÒµÖ¸±ê¸ú×Ù¡£KibanaÌṩǿʢµÄËÑË÷¡¢¹ýÂ˺ͿÉÊÓ»¯¹¦Ð§£¬ÊÊÓÃÓÚ´ó¹æÄ£Êý¾Ý´¦Öóͷ£ºÍչʾ¡£Ëü³£ÓÃÓÚÇå¾²ÊÂÎñ¼à¿Ø¡¢ÈÕÖ¾ÆÊÎö¡¢ÓªÒµÖÇÄܵÈÁìÓò£¬ÊÇElastic Stack£¨°üÀ¨Elasticsearch¡¢LogstashºÍBeats£©µÄ½¹µã×é¼þÖ®Ò»¡£
2025Äê5ÔÂ7ÈÕ£¬×ðÁú¿Ê±¼¯ÍÅVSRC¼à²âµ½Elastic¹Ù·½Ðû²¼µÄÇ徲ͨ¸æ£¬Ö¸³öElastic Kibana±£´æÔÐÍÎÛȾÎó²î¡£¹¥»÷Õß¿Éͨ¹ýÈ«ÐĽṹµÄHTTPÇëÇó£¬Ê¹ÓÃKibanaµÄ»úеѧϰºÍ±¨¸æ¶Ëµã£¬¿ÉÄܵ¼ÖÂí§Òâ´úÂëÖ´ÐУ¬Îó²î¼¶±ðÑÏÖØ£¬Îó²îÆÀ·Ö9.1·Ö¡£
¶þ¡¢Ó°Ïì¹æÄ£
8.3.0 <= Kibana <= 8.17.5
Èý¡¢Çå¾²²½·¥
3.1 Éý¼¶°æ±¾
¹Ù·½ÒÑÐû²¼Çå¾²¸üУ¬½¨ÒéÊÜÓ°ÏìÓû§¾¡¿ìÉý¼¶ÖÁ8.17.6¡¢8.18.1»ò9.0.1°æ±¾¡£
ÏÂÔØÁ´½Ó£ºhttps://github.com/elastic/kibana/releases
3.2 ÔÝʱ²½·¥
¹ØÓÚÎÞ·¨Éý¼¶µÄÓû§£¬¿ÉÒÔͨ¹ý½ûÓûúеѧϰ»ò±¨¸æ¹¦Ð§À´»º½âΣº¦¡£×ÔÍйܺÍElastic Cloud°²ÅŵÄÓû§¿ÉÔÚkibana.ymlÎļþÖÐÌí¼Óxpack.ml.enabled: falseÀ´½ûÓûúеѧϰ¹¦Ð§£»Èô½öÐè½ûÓÃÒì³£¼ì²â¹¦Ð§£¬×ÔÍйÜÓû§¿ÉÌí¼Óxpack.ml.ad.enabled: false¡£Í¬Ê±£¬Óû§Ò²¿ÉÒÔͨ¹ýÔÚkibana.ymlÎļþÖÐÌí¼Óxpack.reporting.enabled: falseÀ´½ûÓñ¨¸æ¹¦Ð§¡£
3.3 ͨÓý¨Òé
? °´ÆÚ¸üÐÂϵͳ²¹¶¡£¬ïÔÌϵͳÎó²î£¬ÌáÉý·þÎñÆ÷µÄÇå¾²ÐÔ¡£
3.4 ²Î¿¼Á´½Ó
https://discuss.elastic.co/t/kibana-8-17-6-8-18-1-or-9-0-1-security-update-esa-2025-07/377868


¾©¹«Íø°²±¸11010802024551ºÅ