Lucene search

K
cve[email protected]CVE-2023-31414
HistoryMay 04, 2023 - 9:15 p.m.

CVE-2023-31414

2023-05-0421:15:11
CWE-94
web.nvd.nist.gov
27
kibana
arbitrary code execution
cve-2023-31414
security
nvd

8.8 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

9 High

AI Score

Confidence

High

0.002 Low

EPSS

Percentile

52.3%

Kibana versions 8.0.0 through 8.7.0 contain an arbitrary code execution flaw. An attacker with write access to Kibana yaml or env configuration could add a specific payload that will attempt to execute JavaScript code. This could lead to the attacker executing arbitrary commands on the host system with permissions of the Kibana process.

Affected configurations

NVD
Node
elastickibanaRange8.0.08.7.0
CPENameOperatorVersion
elastic:kibanaelastic kibanale8.7.0

CNA Affected

[
  {
    "vendor": "Elastic",
    "product": "Kibana",
    "versions": [
      {
        "version": "versions 8.0.0 through 8.7.0",
        "status": "affected"
      }
    ]
  }
]

8.8 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

9 High

AI Score

Confidence

High

0.002 Low

EPSS

Percentile

52.3%

Related for CVE-2023-31414