Sploitus

CVE-2023-31414

No indexed exploits for CVE-2023-31414 yet

Kibana versions 8.0.0 through 8.7.0 contain an arbitrary code execution flaw. An attacker with write access to Kibana yaml or env configuration could add a specific payload that will attempt to execute JavaScript code. This could lead to the attacker executing arbitrary commands on the host system with permissions of the Kibana process.

Affected products
Kibana
Elastic Kibana
≤ 8.7.0
Fix
Available
CVSS 3.1
8.8 HIGH
EPSS
0.6% (45th percentile)
Weakness
CWE-94
NVD status
Modified
Published
2023-05-04
CVE-2023-31414 at NVD
Authoritative description, scoring and affected products

No indexed exploits for CVE-2023-31414 yet

Our index is partial: it proves presence, never absence

No exploit for CVE-2023-31414 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.