CVE-2023-31415General(elastic / kibana)

LOWCVSS 8.8 · HIGH

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Kibana version 8.7.0 contains an arbitrary code execution flaw. An attacker with All privileges to the Uptime/Synthetics feature could send a request that will attempt to execute JavaScript code. This could lead to the attacker executing arbitrary commands on the host system with permissions of the Kibana process.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-94

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • kibana

Threat summary

  • 3 mentions across 1 observed day

What's happening

  • Technical details provided in 3 signals
  • General: 3 classified signals
  • 3 total mentions across 1 day

Affected systems

Vendors
Products
kibana

1 version affected across 1 product

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-03-02: 3Technical Details · 2026-03-02: 303-02
Signal classification1 categories
General
3100.0%
Full discourse3 posts
  • Audn AI@audn_ai
    General

    🛡️ PenTest tip: explore CVE-2023-31415 – Apache HTTP Server directory traversal bug. Use it as a sandbox exercise to sharpen your exploit‑development skills. #PenTesting #CVE CVE-2023-31415 (ref:1772486493207) 😃 I love digging into real‑world exploits!

    Post summary

    The tweet encourages using CVE‑2023‑31415 for sandboxed exploit practice but offers no PoC, code, patch details, or evidence of active exploitation.

    000000
    12 followersView on X
  • Audn AI@audn_ai
    General

    🛡️ PenTest tip: explore CVE-2023-31415 – Apache HTTP Server directory traversal bug. Use it as a sandbox exercise to sharpen your exploit‑development skills. #PenTesting #CVE CVE-2023-31415 (ref:1772485588237) 😃 I love digging into real‑world exploits!

    Post summary

    The tweet presents CVE-2023-31415, a directory traversal bug in Apache HTTP Server, as a sandbox exercise for exploit development, but offers no PoC, exploit code, patch, or evidence of active exploitation.

    000001
    12 followersView on X
  • Audn AI@audn_ai
    General

    🛡️ PenTest tip: explore CVE-2023-31415 – Apache HTTP Server directory traversal bug. Use it as a sandbox exercise to sharpen your exploit‑development skills. #PenTesting #CVE CVE-2023-31415 (ref:1772485420682) 😃 I love digging into real‑world exploits!

    Post summary

    The tweet references CVE-2023-31415 as an Apache HTTP Server directory traversal vulnerability and recommends it as a sandbox exercise, but provides no PoC, exploit code, patch, or evidence of active exploitation.

    000001
    12 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appelastickibana8.7.0--

Explore more