Insufficiently Protected Credentials in the Crowdstrike connector can lead to Crowdstrike credentials being leaked. A malicious user can access cached credentials from a Crowdstrike connector in another space by creating and running a Crowdstrike connector in a space to which they have access.
{
"cwe_ids": [
"CWE-522"
],
"cna_assigner": "elastic",
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/37xxx/CVE-2025-37728.json"
}{
"extracted_events": [
{
"introduced": "7.0.0"
},
{
"last_affected": "7.17.29"
},
{
"introduced": "8.14.0"
},
{
"last_affected": "8.18.7"
},
{
"introduced": "8.19.0"
},
{
"last_affected": "8.19.4"
},
{
"introduced": "9.0.0"
},
{
"last_affected": "9.0.7"
},
{
"introduced": "9.1.0"
},
{
"last_affected": "9.1.4"
}
],
"source": "AFFECTED_FIELD"
}