216.73.217.6

CVE-2025-37734

· Published 12/11/2025 10:15 · Modified 11/12/2025 21:09

Labels: CVE-2025-37734 2025-11-12CVE-2025-37734CWE-346[email protected][email protected]

Essential information

Published
12/11/2025 10:15
Modified
11/12/2025 21:09
Author
Creator
CVSS
4.3 MEDIUM (v3.1)
CISA KEV
No
CWE
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N

CVSS metrics

Description

Origin Validation Error in Kibana can lead to Server-Side Request Forgery via a forged Origin HTTP header processed by the Observability AI Assistant.

NVD status

Status
Analyzed — CVE has had analysis completed and all data associations made.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
elastic / kibana cpe:2.3:a:elastic:kibana:*:*:*:*:*:*:*:*
elastic / kibana cpe:2.3:a:elastic:kibana:*:*:*:*:*:*:*:*
elastic / kibana cpe:2.3:a:elastic:kibana:9.2.0:*:*:*:*:*:*:*

References