First published: Thu May 04 2023(Updated: )
Kibana version 8.7.0 contains an arbitrary code execution flaw. An attacker with All privileges to the Uptime/Synthetics feature could send a request that will attempt to execute JavaScript code. This could lead to the attacker executing arbitrary commands on the host system with permissions of the Kibana process.
Credit: bressers@elastic.co
Affected Software | Affected Version | How to fix |
---|---|---|
Elastic Kibana | =8.7.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for the Kibana arbitrary code execution flaw in version 8.7.0 is CVE-2023-31415.
CVE-2023-31415 has a severity level of 8.8, which is considered high.
CVE-2023-31415 affects Kibana version 8.7.0.
An attacker with All privileges to the Uptime/Synthetics feature could send a request that will attempt to execute JavaScript code, leading to arbitrary command execution on the host system.
Yes, you can find more information about CVE-2023-31415 in the reference links provided: [link1] [link2]