In Grafana Image Renderer versions 1.0.0 through 4.0.16 a critical severity vulnerability CVE-2025-11539 was detected.This vulnerability allows attackers to achieve remote code execution by writing arbitrary files via the /render/csv endpoint—when the filePath parameter is not validated—which are then loaded by the Chromium process, and affects instances where the default token (authToken) is unchanged or known to the attacker and the endpoint is reachable. To address this issue, users should upgrade Grafana to version 4.0.17 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-11539.
Read more Data AnalyticsIn Redis versions 8.2.1 and below a high severity vulnerability CVE-2025-46817 was detected. Authenticated users can use specially crafted Lua scripts to trigger an integer overflow that may lead to remote code execution. This issue affects all Redis versions with Lua scripting enabled. To address this issue, users should upgrade Redis to version 8.2.2 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-46817.
Read more DatabaseIn Redis versions 8.2.1 and below a high severity vulnerability CVE-2025-49844 was detected. Authenticated users can use a specially crafted Lua script to manipulate the garbage collector, triggering a use-after-free condition that may lead to remote code execution. This issue affects all Redis versions with Lua scripting enabled. To address this issue, users should upgrade Redis to version 8.2.2 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-49844.
Read more DatabaseIn Redis versions 8.2.1 and below a medium severity vulnerability CVE-2025-46819 was detected. Authenticated users can use specially crafted Lua scripts to read out-of-bounds data or crash the server, leading to denial of service (DoS). This issue affects all Redis versions with Lua scripting enabled. To address this issue, users should upgrade Redis to version 8.2.2 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-46819.
Read more DatabaseIn Kibana versions 7.x prior to and including 7.17.29, 8.x from 8.14.0 up to 8.18.7, 8.19.x from 8.19.0 up to 8.19.4, 9.0.x from 9.0.0 up to 9.0.7, and 9.1.x from 9.1.0 up to 9.1.4 a medium severity vulnerability CVE-2025-37728 was detected. Insufficiently protected credentials in the CrowdStrike connector can lead to CrowdStrike credentials being leaked. A malicious user can access cached credentials from a CrowdStrike connector in another space by creating and running a CrowdStrike connector in a space to which they have access. To address this issue, users should update Kibana to versions 8.18.8, 8.19.5, 9.0.8, or 9.1.5. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-37728.
Read more Data AnalyticsIn Kibana versions 7.x prior to and including 7.17.29, 8.x from 8.0.0 up to and including 8.18.7, 8.19.x from 8.19.0 up to and including 8.19.4, 9.0.x from 9.0.0 up to and including 9.0.7, and 9.1.x from 9.1.0 up to and including 9.1.4 a high severity vulnerability CVE-2025-25009 was detected. Improper neutralization of input during web page generation in Kibana can lead to Stored Cross-Site Scripting via case file upload. To address this issue, users should upgrade Kibana to versions 8.18.8, 8.19.5, 9.0.8, or 9.1.5. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-25009.
Read more Data AnalyticsIn Kibana versions from 8.7.0 up to 8.15.0 a medium severity vulnerability CVE-2024-43710 was detected. This vulnerability allows a user with read access to Fleet to exploit the /api/fleet/health_check API to send requests to internal HTTPS endpoints that return JSON, resulting in a server-side request forgery. To address this issue, users should upgrade Kibana to version 8.15.0 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2024-43710.
Read more Data AnalyticsIn Kibana versions up to and including 7.17.22 and 8.0.0 up to and including 8.14.3 a medium severity vulnerability CVE-2024-43708 was detected. This vulnerability allows an authenticated user with read access to any feature in Kibana to send a specially crafted payload to certain UI inputs, causing the server to crash due to improper resource allocation without limits or throttling. To address this issue, users should upgrade Kibana to versions 7.17.23, 8.15.0 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2024-43708.
Read more Data AnalyticsIn Kibana versions from 8.0.0 up to 8.15.0 a high severity vulnerability CVE-2024-43707 was detected. This issue allows a user without access to Fleet to view Elastic Agent policies, which could contain sensitive information depending on the enabled integrations and their versions. To address this vulnerability, users should upgrade Kibana to version 8.15.0 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2024-43707.
Read more Data Analytics