← Back to browse · API

CVE-2023-31415

Severity
CRITICAL
CVSS
9.9
EPSS
0.00957
Risk score
39.93
CISA KEV
No
PoC
No
Published
2023-05-04
Modified
2025-01-29
First seen
2026-08-07
Aliases
EUVD-2023-35726, GHSA-3X5P-XWF4-5G93
Products
Elastic:Kibana version 8.7.0
Sources
euvd EUVD-2023-35726

Description

Kibana version 8.7.0 contains an arbitrary code execution flaw. An attacker with All privileges to the Uptime/Synthetics feature could send a request that will attempt to execute JavaScript code. This could lead to the attacker executing arbitrary commands on the host system with permissions of the Kibana process.

References