CVE-2023-31414

Severity CVSS v4.0:
Pending analysis
Type:
CWE-94 Code Injection
Publication date:
04/05/2023
Last modified:
29/01/2025

Description

Kibana versions 8.0.0 through 8.7.0 contain an arbitrary code execution flaw. An attacker with write access to Kibana yaml or env configuration could add a specific payload that will attempt to execute JavaScript code. This could lead to the attacker executing arbitrary commands on the host system with permissions of the Kibana process.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:elastic:kibana:*:*:*:*:*:*:*:* 8.0.0 (including) 8.7.0 (including)