ESA-2025-06 is a security advisory about a prototype pollution vulnerability. This avisory references the following CVE ID : CVE-2025-25012
Is self-hosted kibana in enterprise version affected?
It is not clear in above advisory.
Thank you.
ESA-2025-06 is a security advisory about a prototype pollution vulnerability. This avisory references the following CVE ID : CVE-2025-25012
Is self-hosted kibana in enterprise version affected?
It is not clear in above advisory.
Thank you.
Hi @fizek,
Welcome to the community! To confirm are you running a self-hosted Kibana instance running with an enterprise license? Which version are you running?
Yes, i'm running a self-hosted Kibana instance with an enterprise license in version 8.17.1.
I wonder do I need to upgrade whole stack to latest 8.17.3.
No worries @fizek. Let me follow up internally and confirm. I'll keep you posted.
Hi @fizek,
I've followed up and since you have an enterprise version we recommend either upgrading or following the xpack.integration_assistant.enabled: false
remediation as covered in the announcement here.
Hope that helps!
I know I already marked your answer as the solution, but I have an additional (related) question.
What does xpack.integration_assistant.enabled: false
actually do? I couldn't find anything relevant in the documentation.
© 2020. All Rights Reserved - Elasticsearch
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant logo are trademarks of the Apache Software Foundation in the United States and/or other countries.