Versions (relevant - OpenSearch/Dashboard/Server OS/Browser):
Opensearch 2.17.1
Dashboard 2.17.1
Describe the issue :
Announcements
Security Announcements
Kibana arbitrary code execution via prototype pollution (ESA-2025-06) Prototype pollution in Kibana leads to arbitrary code execution via a crafted file upload and specifically crafted HTTP requests. In Kibana versions >= 8.15.0 and <...
Reading time: 1 mins š
Likes: 2 ā¤
is ESA-2025-06 (a security issue for kibana >= 8.15.0 and < 8.17.3) relevant to opensearch dashboards?
I know that it was forked in kibana 7.10.2, Iām just trying to be abundantly cautious here.
1 Like
mz123
March 18, 2025, 8:28am
2
Is there any information about that?
kris
March 24, 2025, 9:03pm
3
@AMoo-Miki @kavilla @ashwinpc - can you answer this one? Looks like it is inquiring about CVE-2025-25015 - would that have any relevance / concern?
thanks