CVE-2025-37734
BaseFortify
Publication date: 2025-11-12
Last updated on: 2025-12-11
Assigner: Elastic
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| elastic | kibana | From 8.12.0 (inc) to 8.19.7 (exc) |
| elastic | kibana | From 9.1.0 (inc) to 9.1.7 (exc) |
| elastic | kibana | 9.2.0 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-346 | The product does not properly verify that the source of data or communication is valid. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability is an Origin Validation Error in Kibana that can lead to Server-Side Request Forgery (SSRF). It occurs when a forged Origin HTTP header is processed by the Observability AI Assistant, potentially allowing an attacker to make unauthorized requests from the server.
How can this vulnerability impact me? :
The vulnerability can allow an attacker to perform Server-Side Request Forgery, which may lead to unauthorized internal or external requests being made by the server. This can potentially be used to access internal resources or services that are not normally accessible, impacting the security of your system.