Insufficiently Protected Credentials in the Crowdstrike connector can lead to Crowdstrike credentials being leaked. A malicious user can access cached credentials from a Crowdstrike connector in another space by creating and running a Crowdstrike connector in a space to which they have access.
                
            References
                    Configurations
                    No configuration.
History
                    07 Oct 2025, 16:15
| Type | Values Removed | Values Added | 
|---|---|---|
| References | () https://discuss.elastic.co/t/kibana-crowdstrike-connector-8-18-8-8-19-5-9-0-8-and-9-1-5-security-update-esa-2025-19/382455 - | 
07 Oct 2025, 14:15
| Type | Values Removed | Values Added | 
|---|---|---|
| New CVE | 
Information
                Published : 2025-10-07 14:15
Updated : 2025-10-08 19:38
NVD link : CVE-2025-37728
Mitre link : CVE-2025-37728
CVE.ORG link : CVE-2025-37728
JSON object : View
Products Affected
                No product.
CWE
                
                    
                        
                        CWE-522
                        
            Insufficiently Protected Credentials
