8.8
CVSSv3

CVE-2023-31415

Published: 04/05/2023 Updated: 11/05/2023
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 0

Vulnerability Summary

Kibana version 8.7.0 contains an arbitrary code execution flaw. An attacker with All privileges to the Uptime/Synthetics feature could send a request that will attempt to execute JavaScript code. This could lead to the attacker executing arbitrary commands on the host system with permissions of the Kibana process.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

elastic kibana 8.7.0