CVE-2025-37728
EUVD-2025-3208007.10.2025, 14:15
Insufficiently Protected Credentials in the Crowdstrike connector can lead to Crowdstrike credentials being leaked. A malicious user can access cached credentials from a Crowdstrike connector in another space by creating and running a Crowdstrike connector in a space to which they have access.Enginsight
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| elastic | kibana | 7.0.0 ≤ 𝑥 ≤ 7.17.29 | CNA |
| elastic | kibana | 8.14.0 ≤ 𝑥 ≤ 8.18.7 | CNA |
| elastic | kibana | 8.19.0 ≤ 𝑥 ≤ 8.19.4 | CNA |
| elastic | kibana | 9.0.0 ≤ 𝑥 ≤ 9.0.7 | CNA |
| elastic | kibana | 9.1.0 ≤ 𝑥 ≤ 9.1.4 | CNA |
Common Weakness Enumeration