Sploitus

CVE-2023-31415

No indexed exploits for CVE-2023-31415 yet

Kibana version 8.7.0 contains an arbitrary code execution flaw. An attacker with All privileges to the Uptime/Synthetics feature could send a request that will attempt to execute JavaScript code. This could lead to the attacker executing arbitrary commands on the host system with permissions of the Kibana process.

Affected products
Kibana
Elastic Kibana
= 8.7.0
Fix
Available
CVSS 3.1
9.9 CRITICAL
EPSS
1.0% (58th percentile)
Weakness
CWE-94
NVD status
Modified
Published
2023-05-04
CVE-2023-31415 at NVD
Authoritative description, scoring and affected products

No indexed exploits for CVE-2023-31415 yet

Our index is partial: it proves presence, never absence

No exploit for CVE-2023-31415 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.