¡¾Îó²îͨ¸æ¡¿Kibana ÔÐÍÎÛȾµ¼ÖÂí§Òâ´úÂëÖ´ÐÐÎó²î (CVE-2025-25014)
Ðû²¼Ê±¼ä 2025-05-07Ò»¡¢Îó²î¸ÅÊö
Îó²îÃû³Æ | Kibana ÔÐÍÎÛȾµ¼ÖÂí§Òâ´úÂëÖ´ÐÐÎó²î | ||
CVE ID | CVE-2025-25014 | ||
Îó²îÀàÐÍ | ÔÐÍÎÛȾ | ·¢Ã÷ʱ¼ä | 2025-05-07 |
Îó²îÆÀ·Ö | 9.1 | Îó²îÆ·¼¶ | ÑÏÖØ |
¹¥»÷ÏòÁ¿ | ÍøÂç | ËùÐèȨÏÞ | ¸ß |
ʹÓÃÄÑ¶È | µÍ | Óû§½»»¥ | ²»ÐèÒª |
PoC/EXP | δ¹ûÕæ | ÔÚҰʹÓà | δ·¢Ã÷ |
Elastic KibanaÊÇÒ»¸ö¿ªÔ´Êý¾Ý¿ÉÊÓ»¯ºÍÆÊÎöƽ̨£¬£¬£¬£¬£¬×¨ÎªÓëElasticsearchÅäºÏʹÓöøÉè¼Æ¡£¡£¡£¡£ËüÔÊÐíÓû§Í¨¹ýͼÐνçÃæÖ±¹ÛµØÕ¹Ê¾ºÍ̽Ë÷Êý¾Ý£¬£¬£¬£¬£¬Ö§³ÖʵʱÊý¾ÝÆÊÎö¡¢ÈÕÖ¾¼à¿ØºÍÓªÒµÖ¸±ê¸ú×Ù¡£¡£¡£¡£KibanaÌṩǿʢµÄËÑË÷¡¢¹ýÂ˺ͿÉÊÓ»¯¹¦Ð§£¬£¬£¬£¬£¬ÊÊÓÃÓÚ´ó¹æÄ£Êý¾Ý´¦Öóͷ£ºÍչʾ¡£¡£¡£¡£Ëü³£ÓÃÓÚÇå¾²ÊÂÎñ¼à¿Ø¡¢ÈÕÖ¾ÆÊÎö¡¢ÓªÒµÖÇÄܵÈÁìÓò£¬£¬£¬£¬£¬ÊÇElastic Stack£¨°üÀ¨Elasticsearch¡¢LogstashºÍBeats£©µÄ½¹µã×é¼þÖ®Ò»¡£¡£¡£¡£
2025Äê5ÔÂ7ÈÕ£¬£¬£¬£¬£¬¿Ðý¹ú¼ÊÓÎÏ·¼¯ÍÅVSRC¼à²âµ½Elastic¹Ù·½Ðû²¼µÄÇ徲ͨ¸æ£¬£¬£¬£¬£¬Ö¸³öElastic Kibana±£´æÔÐÍÎÛȾÎó²î¡£¡£¡£¡£¹¥»÷Õß¿Éͨ¹ýÈ«ÐĽṹµÄHTTPÇëÇ󣬣¬£¬£¬£¬Ê¹ÓÃKibanaµÄ»úеѧϰºÍ±¨¸æ¶Ëµã£¬£¬£¬£¬£¬¿ÉÄܵ¼ÖÂí§Òâ´úÂëÖ´ÐУ¬£¬£¬£¬£¬Îó²î¼¶±ðÑÏÖØ£¬£¬£¬£¬£¬Îó²îÆÀ·Ö9.1·Ö¡£¡£¡£¡£
¶þ¡¢Ó°Ïì¹æÄ£
8.3.0 <= Kibana <= 8.17.5
Èý¡¢Çå¾²²½·¥
3.1 Éý¼¶°æ±¾
¹Ù·½ÒÑÐû²¼Çå¾²¸üУ¬£¬£¬£¬£¬½¨ÒéÊÜÓ°ÏìÓû§¾¡¿ìÉý¼¶ÖÁ8.17.6¡¢8.18.1»ò9.0.1°æ±¾¡£¡£¡£¡£
ÏÂÔØÁ´½Ó£ºhttps://github.com/elastic/kibana/releases
3.2 ÔÝʱ²½·¥
¹ØÓÚÎÞ·¨Éý¼¶µÄÓû§£¬£¬£¬£¬£¬¿ÉÒÔͨ¹ý½ûÓûúеѧϰ»ò±¨¸æ¹¦Ð§À´»º½âΣº¦¡£¡£¡£¡£×ÔÍйܺÍElastic Cloud°²ÅŵÄÓû§¿ÉÔÚkibana.ymlÎļþÖÐÌí¼Óxpack.ml.enabled: falseÀ´½ûÓûúеѧϰ¹¦Ð§£»£»£»£»£»£»Èô½öÐè½ûÓÃÒì³£¼ì²â¹¦Ð§£¬£¬£¬£¬£¬×ÔÍйÜÓû§¿ÉÌí¼Óxpack.ml.ad.enabled: false¡£¡£¡£¡£Í¬Ê±£¬£¬£¬£¬£¬Óû§Ò²¿ÉÒÔͨ¹ýÔÚkibana.ymlÎļþÖÐÌí¼Óxpack.reporting.enabled: falseÀ´½ûÓñ¨¸æ¹¦Ð§¡£¡£¡£¡£
3.3 ͨÓý¨Òé
? °´ÆÚ¸üÐÂϵͳ²¹¶¡£¬£¬£¬£¬£¬ïÔÌϵͳÎó²î£¬£¬£¬£¬£¬ÌáÉýЧÀÍÆ÷µÄÇå¾²ÐÔ¡£¡£¡£¡£
3.4 ²Î¿¼Á´½Ó
https://discuss.elastic.co/t/kibana-8-17-6-8-18-1-or-9-0-1-security-update-esa-2025-07/377868