CVE-2023-31415

CVSS V2 None CVSS V3 None
Description
Kibana version 8.7.0 contains an arbitrary code execution flaw. An attacker with All privileges to the Uptime/Synthetics feature could send a request that will attempt to execute JavaScript code. This could lead to the attacker executing arbitrary commands on the host system with permissions of the Kibana process.
Overview
  • CVE ID
  • CVE-2023-31415
  • Assigner
  • bressers@elastic.co
  • Vulnerability Status
  • Received
  • Published Version
  • 2023-05-04T21:15:11
  • Last Modified Date
  • 2023-05-04T21:15:11
History
Created Old Value New Value Data Type Notes
2023-05-04 22:02:42 Added to TrackCVE
2023-05-04 22:02:46 Weakness Enumeration new