Insufficiently Protected Credentials in the Crowdstrike connector can lead to Crowdstrike credentials being leaked. A malicious user can access cached credentials from a Crowdstrike connector in another space by creating and running a Crowdstrike connector in a space to which they have access.
References
Configurations
No configuration.
History
07 Oct 2025, 16:15
Type | Values Removed | Values Added |
---|---|---|
References | () https://discuss.elastic.co/t/kibana-crowdstrike-connector-8-18-8-8-19-5-9-0-8-and-9-1-5-security-update-esa-2025-19/382455 - |
07 Oct 2025, 14:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-10-07 14:15
Updated : 2025-10-08 19:38
NVD link : CVE-2025-37728
Mitre link : CVE-2025-37728
CVE.ORG link : CVE-2025-37728
JSON object : View
Products Affected
No product.
CWE
CWE-522
Insufficiently Protected Credentials