Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-35726 | Kibana version 8.7.0 contains an arbitrary code execution flaw. An attacker with All privileges to the Uptime/Synthetics feature could send a request that will attempt to execute JavaScript code. This could lead to the attacker executing arbitrary commands on the host system with permissions of the Kibana process. |
Wed, 29 Jan 2025 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
ssvc
|
Status: PUBLISHED
Assigner: elastic
Published:
Updated: 2025-01-29T18:00:20.942Z
Reserved: 2023-04-27T00:00:00.000Z
Link: CVE-2023-31415
Updated: 2024-08-02T14:53:30.700Z
Status : Modified
Published: 2023-05-04T21:15:11.760
Modified: 2025-01-29T18:15:46.620
Link: CVE-2023-31415
No data.
OpenCVE Enrichment
No data.
EUVD