¡¾Îó²îͨ¸æ¡¿Kibana Ô­ÐÍÎÛȾµ¼ÖÂí§Òâ´úÂëÖ´ÐÐÎó²î (CVE-2025-25014)

Ðû²¼Ê±¼ä 2025-05-07

Ò»¡¢Îó²î¸ÅÊö


Îó²îÃû³Æ

Kibana Ô­ÐÍÎÛȾµ¼ÖÂí§Òâ´úÂëÖ´ÐÐÎó²î

CVE   ID

CVE-2025-25014

Îó²îÀàÐÍ

Ô­ÐÍÎÛȾ

·¢Ã÷ʱ¼ä

2025-05-07

Îó²îÆÀ·Ö

9.1

Îó²îÆ·¼¶

ÑÏÖØ

¹¥»÷ÏòÁ¿

ÍøÂç

ËùÐèȨÏÞ

¸ß

ʹÓÃÄѶÈ

µÍ

Óû§½»»¥

²»ÐèÒª

PoC/EXP

δ¹ûÕæ

ÔÚҰʹÓÃ

δ·¢Ã÷


Elastic KibanaÊÇÒ»¸ö¿ªÔ´Êý¾Ý¿ÉÊÓ»¯ºÍÆÊÎöƽ̨£¬£¬ £¬£¬£¬£¬£¬×¨ÎªÓëElasticsearchÅäºÏʹÓöøÉè¼Æ¡£¡£¡£¡£¡£ËüÔÊÐíÓû§Í¨¹ýͼÐνçÃæÖ±¹ÛµØÕ¹Ê¾ºÍ̽Ë÷Êý¾Ý£¬£¬ £¬£¬£¬£¬£¬Ö§³ÖʵʱÊý¾ÝÆÊÎö¡¢ÈÕÖ¾¼à¿ØºÍÓªÒµÖ¸±ê¸ú×Ù¡£¡£¡£¡£¡£KibanaÌṩǿʢµÄËÑË÷¡¢¹ýÂ˺ͿÉÊÓ»¯¹¦Ð§£¬£¬ £¬£¬£¬£¬£¬ÊÊÓÃÓÚ´ó¹æÄ£Êý¾Ý´¦Öóͷ£ºÍչʾ¡£¡£¡£¡£¡£Ëü³£ÓÃÓÚÇå¾²ÊÂÎñ¼à¿Ø¡¢ÈÕÖ¾ÆÊÎö¡¢ÓªÒµÖÇÄܵÈÁìÓò£¬£¬ £¬£¬£¬£¬£¬ÊÇElastic Stack£¨°üÀ¨Elasticsearch¡¢LogstashºÍBeats£©µÄ½¹µã×é¼þÖ®Ò»¡£¡£¡£¡£¡£


2025Äê5ÔÂ7ÈÕ£¬£¬ £¬£¬£¬£¬£¬¼øºÚµ£±£Íø¼¯ÍÅVSRC¼à²âµ½Elastic¹Ù·½Ðû²¼µÄÇ徲ͨ¸æ£¬£¬ £¬£¬£¬£¬£¬Ö¸³öElastic Kibana±£´æÔ­ÐÍÎÛȾÎó²î¡£¡£¡£¡£¡£¹¥»÷Õß¿Éͨ¹ýÈ«ÐĽṹµÄHTTPÇëÇ󣬣¬ £¬£¬£¬£¬£¬Ê¹ÓÃKibanaµÄ»úеѧϰºÍ±¨¸æ¶Ëµã£¬£¬ £¬£¬£¬£¬£¬¿ÉÄܵ¼ÖÂí§Òâ´úÂëÖ´ÐУ¬£¬ £¬£¬£¬£¬£¬Îó²î¼¶±ðÑÏÖØ£¬£¬ £¬£¬£¬£¬£¬Îó²îÆÀ·Ö9.1·Ö¡£¡£¡£¡£¡£


¶þ¡¢Ó°Ïì¹æÄ£


8.3.0 <= Kibana <= 8.17.5

Kibana 8.18.0
Kibana 9.0.0


Èý¡¢Çå¾²²½·¥


3.1 Éý¼¶°æ±¾


¹Ù·½ÒÑÐû²¼Çå¾²¸üУ¬£¬ £¬£¬£¬£¬£¬½¨ÒéÊÜÓ°ÏìÓû§¾¡¿ìÉý¼¶ÖÁ8.17.6¡¢8.18.1»ò9.0.1°æ±¾¡£¡£¡£¡£¡£


ÏÂÔØÁ´½Ó£ºhttps://github.com/elastic/kibana/releases


3.2 ÔÝʱ²½·¥


¹ØÓÚÎÞ·¨Éý¼¶µÄÓû§£¬£¬ £¬£¬£¬£¬£¬¿ÉÒÔͨ¹ý½ûÓûúеѧϰ»ò±¨¸æ¹¦Ð§À´»º½âΣº¦¡£¡£¡£¡£¡£×ÔÍйܺÍElastic Cloud°²ÅŵÄÓû§¿ÉÔÚkibana.ymlÎļþÖÐÌí¼Óxpack.ml.enabled: falseÀ´½ûÓûúеѧϰ¹¦Ð§£»£»£»£»£»£»Èô½öÐè½ûÓÃÒì³£¼ì²â¹¦Ð§£¬£¬ £¬£¬£¬£¬£¬×ÔÍйÜÓû§¿ÉÌí¼Óxpack.ml.ad.enabled: false¡£¡£¡£¡£¡£Í¬Ê±£¬£¬ £¬£¬£¬£¬£¬Óû§Ò²¿ÉÒÔͨ¹ýÔÚkibana.ymlÎļþÖÐÌí¼Óxpack.reporting.enabled: falseÀ´½ûÓñ¨¸æ¹¦Ð§¡£¡£¡£¡£¡£


3.3 ͨÓý¨Òé


? °´ÆÚ¸üÐÂϵͳ²¹¶¡£¬£¬ £¬£¬£¬£¬£¬ïÔ̭ϵͳÎó²î£¬£¬ £¬£¬£¬£¬£¬ÌáÉýЧÀÍÆ÷µÄÇå¾²ÐÔ¡£¡£¡£¡£¡£

ÔöǿϵͳºÍÍøÂçµÄ»á¼û¿ØÖÆ£¬£¬ £¬£¬£¬£¬£¬Ð޸ķÀ»ðǽսÂÔ£¬£¬ £¬£¬£¬£¬£¬¹Ø±Õ·ÇÐëÒªµÄÓ¦Óö˿ڻòЧÀÍ£¬£¬ £¬£¬£¬£¬£¬ïÔÌ­½«Î£ÏÕЧÀÍ£¨ÈçSSH¡¢RDPµÈ£©Ì»Â¶µ½¹«Íø£¬£¬ £¬£¬£¬£¬£¬ïÔÌ­¹¥»÷Ãæ¡£¡£¡£¡£¡£
ʹÓÃÆóÒµ¼¶Çå¾²²úÆ·£¬£¬ £¬£¬£¬£¬£¬ÌáÉýÆóÒµµÄÍøÂçÇå¾²ÐÔÄÜ¡£¡£¡£¡£¡£
ÔöǿϵͳÓû§ºÍȨÏÞÖÎÀí£¬£¬ £¬£¬£¬£¬£¬ÆôÓöàÒòËØÈÏÖ¤»úÖÆºÍ×îСȨÏÞÔ­Ôò£¬£¬ £¬£¬£¬£¬£¬Óû§ºÍÈí¼þȨÏÞÓ¦¼á³ÖÔÚ×îµÍÏÞ¶È¡£¡£¡£¡£¡£
ÆôÓÃÇ¿ÃÜÂëÕ½ÂÔ²¢ÉèÖÃΪ°´ÆÚÐ޸ġ£¡£¡£¡£¡£


3.4 ²Î¿¼Á´½Ó


https://discuss.elastic.co/t/kibana-8-17-6-8-18-1-or-9-0-1-security-update-esa-2025-07/377868