CVE-2023-31414
https://notcve.org/view.php?id=CVE-2023-31414
Kibana versions 8.0.0 through 8.7.0 contain an arbitrary code execution flaw. An attacker with write access to Kibana yaml or env configuration could add a specific payload that will attempt to execute JavaScript code. This could lead to the attacker executing arbitrary commands on the host system with permissions of the Kibana process. • https://discuss.elastic.co/t/kibana-8-7-1-security-updates/332330 https://www.elastic.co/community/security • CWE-94: Improper Control of Generation of Code ('Code Injection') •
CVE-2023-31415
https://notcve.org/view.php?id=CVE-2023-31415
Kibana version 8.7.0 contains an arbitrary code execution flaw. An attacker with All privileges to the Uptime/Synthetics feature could send a request that will attempt to execute JavaScript code. This could lead to the attacker executing arbitrary commands on the host system with permissions of the Kibana process. • https://discuss.elastic.co/t/kibana-8-7-1-security-updates/332330 https://www.elastic.co/community/security • CWE-94: Improper Control of Generation of Code ('Code Injection') •
CVE-2022-38779
https://notcve.org/view.php?id=CVE-2022-38779
An open redirect issue was discovered in Kibana that could lead to a user being redirected to an arbitrary website if they use a maliciously crafted Kibana URL. • https://discuss.elastic.co/t/kibana-7-17-9-and-8-6-2-security-update/325782 https://www.elastic.co/community/security • CWE-601: URL Redirection to Untrusted Site ('Open Redirect') •
CVE-2022-38778
https://notcve.org/view.php?id=CVE-2022-38778
A flaw (CVE-2022-38900) was discovered in one of Kibana’s third party dependencies, that could allow an authenticated user to perform a request that crashes the Kibana server process. • https://discuss.elastic.co/t/elastic-7-17-9-8-5-0-and-8-6-1-security-update/324661 https://www.elastic.co/community/security • CWE-20: Improper Input Validation •
CVE-2022-38777
https://notcve.org/view.php?id=CVE-2022-38777
An issue was discovered in the rollback feature of Elastic Endpoint Security for Windows, which could allow unprivileged users to elevate their privileges to those of the LocalSystem account. • https://discuss.elastic.co/t/elastic-7-17-9-8-5-0-and-8-6-1-security-update/324661 https://www.elastic.co/community/security • CWE-269: Improper Privilege Management •