ElasticsearchGHSA-285m-vhfq-xx4h
Elasticsearch Improper Handling of Exceptional Conditions
Medium6.5CVE-2023-46673 · Published Nov 22, 2023 · updated Feb 16, 2024
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| org.elasticsearch:elasticsearch Maven | >= 7.0.0, < 7.17.14 | 7.17.14 |
| >= 8.0.0, < 8.10.3 | 8.10.3 |
Details and references
It was identified that malformed scripts used in the script processor of an Ingest Pipeline could cause an Elasticsearch node to crash when calling the Simulate Pipeline API.
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-755
- Also known as
- BIT-elasticsearch-2023-46673, CVE-2023-46673
More Elasticsearch advisories
All Elasticsearch| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Oct 262023 | Elasticsearch vulnerable to Uncontrolled Resource Consumption CVE-2023-31418High7.5fixed in 7.17.13, 8.9.0 | High7.5 | 7.17.13, 8.9.0 |
| Oct 262023 | Elasticsearch allows insertion of sensitive information into log files when using deprecated URIs CVE-2023-31417Medium4.1fixed in 7.17.13, 8.9.2 | Medium4.1 | 7.17.13, 8.9.2 |
| Oct 262023 | Elasticsearch vulnerable to stack overflow in the search API CVE-2023-31419Medium6.5fixed in 7.17.13, 8.9.1 | Medium6.5 | 7.17.13, 8.9.1 |
| Mar 272024 | Elasticsearch Uncontrolled Resource Consumption vulnerability CVE-2024-23450Medium4.9fixed in 7.17.19, 8.13.0 | Medium4.9 | 7.17.19, 8.13.0 |
| Mar 272024 | Elasticsearch Incorrect Authorization vulnerability CVE-2024-23451Medium4.4fixed in 8.13.0 | Medium4.4 | 8.13.0 |
| Mar 292024 | Elasticsearch Uncaught Exception leading to crash CVE-2024-23449Medium4.3fixed in 8.11.1 | Medium4.3 | 8.11.1 |