Kibana Insufficiently Protected Credentials in the CrowdStrike Connector
Vulnerability Description
Insufficiently Protected Credentials in the Crowdstrike connector can lead to Crowdstrike credentials being leaked. A malicious user can access cached credentials from a Crowdstrike connector in another space by creating and running a Crowdstrike connector in a space to which they have access.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-37728
Credits & Attribution
No credits recorded in the NVD database.
More from Elastic
View All →Affected Vendor
Elastic
View all reports →