CVE-2023-31414Code Injection in Kibana

CWE-94Code Injection3 documents3 sources
Severity
8.8HIGHNVD
EPSS
0.3%
top 47.06%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMay 4

Description

Kibana versions 8.0.0 through 8.7.0 contain an arbitrary code execution flaw. An attacker with write access to Kibana yaml or env configuration could add a specific payload that will attempt to execute JavaScript code. This could lead to the attacker executing arbitrary commands on the host system with permissions of the Kibana process.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

Affected Packages2 packages

NVDelastic/kibana8.0.08.7.0
CVEListV5elastic/kibanaversions 8.0.0 through 8.7.0

🔴Vulnerability Details

2
CVEList
CVE-2023-31414: Kibana versions 82023-05-04
GHSA
GHSA-2gwg-52c6-q2hx: Kibana versions 82023-05-04
CVE-2023-31414 — Code Injection in Elastic Kibana | cvebase