CVE-2023-31415: Code Injection
Kibana version 8.7.0 contains an arbitrary code execution flaw. An attacker with All privileges to the Uptime/Synthetics feature could send a request that will attempt to execute JavaScript code. This could lead to the attacker executing arbitrary commands on the host system with permissions of the Kibana process.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for the Kibana arbitrary code execution flaw in version 8.7.0?
The vulnerability ID for the Kibana arbitrary code execution flaw in version 8.7.0 is CVE-2023-31415.
What is the severity of CVE-2023-31415?
CVE-2023-31415 has a severity level of 8.8, which is considered high.
What software versions are affected by CVE-2023-31415?
CVE-2023-31415 affects Kibana version 8.7.0.
How can an attacker exploit CVE-2023-31415?
An attacker with All privileges to the Uptime/Synthetics feature could send a request that will attempt to execute JavaScript code, leading to arbitrary command execution on the host system.
Are there any references regarding CVE-2023-31415?
Yes, you can find more information about CVE-2023-31415 in the reference links provided: [link1] [link2]