Report Incident
× Home Cybertech Africa 2023 2 DPO Rw-CSIRT Website About Rw-CSIRT Alerts Advisories About NCSA Documentation News & Events Topics Contact us Opportunities Privacy Policy

Alert: Kibana Critical Security Update - March 2025

Elastic has released urgent security updates to address a critical vulnerability in Kibana, identified as CVE-2025-25012. This vulnerability could allow attackers to execute arbitrary code on affected servers, posing significant risks to system security.
 
Affected Systems
 
The following Kibana versions are affected:
 
Security Risks
 
The identified vulnerabilities in Kibana could lead to remote code execution, unauthorized data access, privilege escalation, and potential denial-of-service attacks, posing significant threats to system integrity and confidentiality.
 
Recommended Actions
 
To mitigate these risks, The National Cyber Security Authority (NCSA) recommends users and system administrators to:
 
  • Upgrade to the latest supported version of Kibana as soon as possible to ensure continued access to technical support and security patches.

    The recommended software versions to upgrade to is:
  • Kibana Version 8.17.3 or later.  
  • Before performing any updates, ensure that a complete backup of your data is taken to prevent data loss during the upgrade process.
  • After upgrading, monitor your systems for any unusual activity and ensure all security configurations are up to date.
 
For further information and support, please contact the National Cyber Security Authority (NCSA) by emailto rwcsirt@ncsa.gov.rw or call us on 9009
 
References

07 March 2025

© 2025 National Cyber Security Authority