CVE-2023-31415

Source
https://cve.org/CVERecord?id=CVE-2023-31415
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-31415.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2023-31415
Published
2023-05-04T21:15:11.760Z
Modified
2026-04-10T04:57:37.686427Z
Severity
  • 8.8 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

Kibana version 8.7.0 contains an arbitrary code execution flaw. An attacker with All privileges to the Uptime/Synthetics feature could send a request that will attempt to execute JavaScript code. This could lead to the attacker executing arbitrary commands on the host system with permissions of the Kibana process.

References

Affected packages

Git / github.com/elastic/kibana

Affected ranges

Type
GIT
Repo
https://github.com/elastic/kibana
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Database specific
{
    "versions": [
        {
            "introduced": "0"
        },
        {
            "last_affected": "8.7.0"
        }
    ]
}

Affected versions

7.*
7.0-known-good
v4.*
v4.0.0-beta1
v4.0.0-beta1.1
v4.0.0-beta2
v4.0.0-beta3
v4.2.0-beta1
v5.*
v5.0.0-alpha5
v6.*
v6.0.0-alpha1
v6.0.0-alpha2
v7.*
v7.0.0-alpha1
v8.*
v8.0.0-alpha1
v8.0.0-alpha2
v8.7.0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-31415.json"