Back to overview

CVE-2023-31415

CRITICAL
9.9
CVSS 3.1
Description
Kibana version 8.7.0 contains an arbitrary code execution flaw. An attacker with All privileges to the Uptime/Synthetics feature could send a request that will attempt to execute JavaScript code. This could lead to the attacker executing arbitrary commands on the host system with permissions of the Kibana process.

Metadata

CVE ID
CVE-2023-31415
State
PUBLISHED
Assigner
elastic
Reserved
2023-04-27 00:00 UTC
Published
2023-05-04 00:00 UTC
Last updated
2025-01-29 18:00 UTC
Primary CWE
CWE-94
CWE-94: Improper Control of Generation of Code
Vendor / Product
Elastic / Kibana
Sources
cve.org  ·  NVD

Severity & Metrics

9.9 CRITICAL CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
SSVC — CISA Coordinator
Exploitation
none
Automatable
no
Tech. Impact
total
Affected products (1)
VendorProductPlatformVersions
Elastic Kibana version 8.7.0
Weakness (CWE)
CWESourceDescription
CWE-94 cna CWE-94: Improper Control of Generation of Code
CVSS scores (1)
ScoreSeverityVersionSourceVector
9.9 CRITICAL 3.1 adp CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Back to overview