# Kibana 8.16.4 and 8.17.2 Security Update (ESA-2025-02)

**URL:** https://discuss.elastic.co/t/kibana-8-16-4-and-8-17-2-security-update-esa-2025-02/376918
**Category:** Security Announcements
**Created:** [April 8, 2025, 3:53pm UTC](https://discuss.elastic.co/t/kibana-8-16-4-and-8-17-2-security-update-esa-2025-02/376918 "2025-04-08T15:53:15Z")
**Posts on this page:** 1
**Page:** 1

<div class="post-metadata">

### Author: ![ismisepaul](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ismisepaul/32/102235_2.png) [@ismisepaul](https://discuss.elastic.co/u/ismisepaul)
#### Post date: [April 8, 2025, 3:53pm UTC](https://discuss.elastic.co/t/kibana-8-16-4-and-8-17-2-security-update-esa-2025-02/376918/1 "2025-04-08T15:53:15Z")

</div>

**Kibana Prototype Pollution can lead to code injection (ESA-2025-02)**

Prototype Pollution in Kibana can lead to code injection via unrestricted file upload combined with path traversal.

**Affected Versions:**  
Kibana versions 8.16.1 up to and including 8.16.3, and 8.17.0 up to and including 8.17.1

**Solutions and Mitigations:**  
Users should upgrade to version 8.16.4 and 8.17.2 or higher

**For Users that cannot upgrade:**  
Customers who cannot upgrade to 8.16.4 or 8.17.2 can disable the integration assistant by setting `xpack.integration_assistant.enabled: false` in their `kibana.yml` configuration file.

**Severity:** CVSS v3.1: 8.7(High) - CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N  
**CVE ID:** CVE-2024-12556

* * *

2025-06-05: Previous the communicated affected versions alluded that 8.16.4 was affected. This has been updated to clarify that 8.16.4 is not affected.
