← Back to CVE List
CVE-2025-68385NVD
Vulnerability Summary
Improper neutralization of input during web page generation ('Cross-site Scripting') (CWE-79) allows an authenticated user to embed a malicious script in content that will be served to web browsers causing cross-site scripting (XSS) (CAPEC-63) via a method in Vega bypassing a previous Vega XSS mitigation.
CVSS v3.1 Base Metrics — Score 7.2 (HIGH)
Attack VectorNetwork
Attack ComplexityLow
Privileges RequiredNone
User InteractionNone
ScopeChanged
ConfidentialityLow
IntegrityLow
AvailabilityNone
Affected & Patched Versions
- Elastic Kibana >= 7.0.0 and <= 7.17.29
- Elastic Kibana >= 8.0.0 and < 8.19.9
- Elastic Kibana >= 9.0.0 and < 9.1.9
- Elastic Kibana >= 9.2.0 and < 9.2.3
- Elastic Kibana 8.19.9
- Elastic Kibana 9.1.9
- Elastic Kibana 9.2.3