CVE-2023-31414: Code Injection
Kibana versions 8.0.0 through 8.7.0 contain an arbitrary code execution flaw. An attacker with write access to Kibana yaml or env configuration could add a specific payload that will attempt to execute JavaScript code. This could lead to the attacker executing arbitrary commands on the host system with permissions of the Kibana process.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2023-31414.
What is the severity of CVE-2023-31414?
The severity of CVE-2023-31414 is high with a severity value of 8.8.
Which versions of Kibana are affected by CVE-2023-31414?
Kibana versions 8.0.0 through 8.7.0 are affected by CVE-2023-31414.
How can an attacker exploit CVE-2023-31414?
An attacker with write access to Kibana yaml or env configuration could add a specific payload that attempts to execute JavaScript code, leading to arbitrary command execution on the host system.
Where can I find more information about CVE-2023-31414?
You can find more information about CVE-2023-31414 on the Elastic Security website and the Elastic community forums.