¡¾Îó²îͨ¸æ¡¿Kibana Ô­ÐÍÎÛȾµ¼ÖÂí§Òâ´úÂëÖ´ÐÐÎó²î (CVE-2025-25014)

Ðû²¼Ê±¼ä 2025-05-07

Ò»¡¢Îó²î¸ÅÊö


Îó²îÃû³Æ

Kibana Ô­ÐÍÎÛȾµ¼ÖÂí§Òâ´úÂëÖ´ÐÐÎó²î

CVE   ID

CVE-2025-25014

Îó²îÀàÐÍ

Ô­ÐÍÎÛȾ

·¢Ã÷ʱ¼ä

2025-05-07

Îó²îÆÀ·Ö

9.1

Îó²îÆ·¼¶

ÑÏÖØ

¹¥»÷ÏòÁ¿

ÍøÂç

ËùÐèȨÏÞ

¸ß

ʹÓÃÄѶÈ

µÍ

Óû§½»»¥

²»ÐèÒª

PoC/EXP

δ¹ûÕæ

ÔÚҰʹÓÃ

δ·¢Ã÷


Elastic KibanaÊÇÒ»¸ö¿ªÔ´Êý¾Ý¿ÉÊÓ»¯ºÍÆÊÎöƽ̨£¬£¬ £¬£¬£¬×¨ÎªÓëElasticsearchÅäºÏʹÓöøÉè¼Æ¡£ ¡£¡£¡£ËüÔÊÐíÓû§Í¨¹ýͼÐνçÃæÖ±¹ÛµØÕ¹Ê¾ºÍ̽Ë÷Êý¾Ý£¬£¬ £¬£¬£¬Ö§³ÖʵʱÊý¾ÝÆÊÎö¡¢ÈÕÖ¾¼à¿ØºÍÓªÒµÖ¸±ê¸ú×Ù¡£ ¡£¡£¡£KibanaÌṩǿʢµÄËÑË÷¡¢¹ýÂ˺ͿÉÊÓ»¯¹¦Ð§£¬£¬ £¬£¬£¬ÊÊÓÃÓÚ´ó¹æÄ£Êý¾Ý´¦Öóͷ£ºÍչʾ¡£ ¡£¡£¡£Ëü³£ÓÃÓÚÇå¾²ÊÂÎñ¼à¿Ø¡¢ÈÕÖ¾ÆÊÎö¡¢ÓªÒµÖÇÄܵÈÁìÓò£¬£¬ £¬£¬£¬ÊÇElastic Stack£¨°üÀ¨Elasticsearch¡¢LogstashºÍBeats£©µÄ½¹µã×é¼þÖ®Ò»¡£ ¡£¡£¡£


2025Äê5ÔÂ7ÈÕ£¬£¬ £¬£¬£¬¿­Ðý¹ú¼ÊÓÎÏ·¼¯ÍÅVSRC¼à²âµ½Elastic¹Ù·½Ðû²¼µÄÇ徲ͨ¸æ£¬£¬ £¬£¬£¬Ö¸³öElastic Kibana±£´æÔ­ÐÍÎÛȾÎó²î¡£ ¡£¡£¡£¹¥»÷Õß¿Éͨ¹ýÈ«ÐĽṹµÄHTTPÇëÇ󣬣¬ £¬£¬£¬Ê¹ÓÃKibanaµÄ»úеѧϰºÍ±¨¸æ¶Ëµã£¬£¬ £¬£¬£¬¿ÉÄܵ¼ÖÂí§Òâ´úÂëÖ´ÐУ¬£¬ £¬£¬£¬Îó²î¼¶±ðÑÏÖØ£¬£¬ £¬£¬£¬Îó²îÆÀ·Ö9.1·Ö¡£ ¡£¡£¡£


¶þ¡¢Ó°Ïì¹æÄ£


8.3.0 <= Kibana <= 8.17.5

Kibana 8.18.0
Kibana 9.0.0


Èý¡¢Çå¾²²½·¥


3.1 Éý¼¶°æ±¾


¹Ù·½ÒÑÐû²¼Çå¾²¸üУ¬£¬ £¬£¬£¬½¨ÒéÊÜÓ°ÏìÓû§¾¡¿ìÉý¼¶ÖÁ8.17.6¡¢8.18.1»ò9.0.1°æ±¾¡£ ¡£¡£¡£


ÏÂÔØÁ´½Ó£ºhttps://github.com/elastic/kibana/releases


3.2 ÔÝʱ²½·¥


¹ØÓÚÎÞ·¨Éý¼¶µÄÓû§£¬£¬ £¬£¬£¬¿ÉÒÔͨ¹ý½ûÓûúеѧϰ»ò±¨¸æ¹¦Ð§À´»º½âΣº¦¡£ ¡£¡£¡£×ÔÍйܺÍElastic Cloud°²ÅŵÄÓû§¿ÉÔÚkibana.ymlÎļþÖÐÌí¼Óxpack.ml.enabled: falseÀ´½ûÓûúеѧϰ¹¦Ð§£»£»£»£»£»£»Èô½öÐè½ûÓÃÒì³£¼ì²â¹¦Ð§£¬£¬ £¬£¬£¬×ÔÍйÜÓû§¿ÉÌí¼Óxpack.ml.ad.enabled: false¡£ ¡£¡£¡£Í¬Ê±£¬£¬ £¬£¬£¬Óû§Ò²¿ÉÒÔͨ¹ýÔÚkibana.ymlÎļþÖÐÌí¼Óxpack.reporting.enabled: falseÀ´½ûÓñ¨¸æ¹¦Ð§¡£ ¡£¡£¡£


3.3 ͨÓý¨Òé


? °´ÆÚ¸üÐÂϵͳ²¹¶¡£¬£¬ £¬£¬£¬ïÔ̭ϵͳÎó²î£¬£¬ £¬£¬£¬ÌáÉýЧÀÍÆ÷µÄÇå¾²ÐÔ¡£ ¡£¡£¡£

ÔöǿϵͳºÍÍøÂçµÄ»á¼û¿ØÖÆ£¬£¬ £¬£¬£¬Ð޸ķÀ»ðǽսÂÔ£¬£¬ £¬£¬£¬¹Ø±Õ·ÇÐëÒªµÄÓ¦Óö˿ڻòЧÀÍ£¬£¬ £¬£¬£¬ïÔÌ­½«Î£ÏÕЧÀÍ£¨ÈçSSH¡¢RDPµÈ£©Ì»Â¶µ½¹«Íø£¬£¬ £¬£¬£¬ïÔÌ­¹¥»÷Ãæ¡£ ¡£¡£¡£
ʹÓÃÆóÒµ¼¶Çå¾²²úÆ·£¬£¬ £¬£¬£¬ÌáÉýÆóÒµµÄÍøÂçÇå¾²ÐÔÄÜ¡£ ¡£¡£¡£
ÔöǿϵͳÓû§ºÍȨÏÞÖÎÀí£¬£¬ £¬£¬£¬ÆôÓöàÒòËØÈÏÖ¤»úÖÆºÍ×îСȨÏÞÔ­Ôò£¬£¬ £¬£¬£¬Óû§ºÍÈí¼þȨÏÞÓ¦¼á³ÖÔÚ×îµÍÏÞ¶È¡£ ¡£¡£¡£
ÆôÓÃÇ¿ÃÜÂëÕ½ÂÔ²¢ÉèÖÃΪ°´ÆÚÐ޸ġ£ ¡£¡£¡£


3.4 ²Î¿¼Á´½Ó


https://discuss.elastic.co/t/kibana-8-17-6-8-18-1-or-9-0-1-security-update-esa-2025-07/377868