Skip to content
ElasticsearchGHSA-pw39-f3m5-cxfc

Elasticsearch Uncaught Exception leading to crash

Medium4.3CVE-2024-23449 · Published Mar 29, 2024 · updated May 27, 2025

GitHub advisory

Affected versions

PackageAffectedFixed in
org.elasticsearch:elasticsearch
Maven
>= 8.4.0, < 8.11.18.11.1
Details and references

An uncaught exception in Elasticsearch >= 8.4.0 and < 8.11.1 occurs when an encrypted PDF is passed to an attachment processor through the REST API. The Elasticsearch ingest node that attempts to parse the PDF file will crash. This does not happen with password-protected PDF files or with unencrypted PDF files.

CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
Severity from
GitHub (reviewed advisory)
Weakness
CWE-248
Also known as
BIT-elasticsearch-2024-23449, CVE-2024-23449

More Elasticsearch advisories

All Elasticsearch
DateAdvisory
Mar 272024Elasticsearch Incorrect Authorization vulnerability
CVE-2024-23451Medium4.4fixed in 8.13.0
Mar 272024Elasticsearch Uncontrolled Resource Consumption vulnerability
CVE-2024-23450Medium4.9fixed in 7.17.19, 8.13.0
Jun 132024Elasticsearch StackOverflow vulnerability
CVE-2024-37280Medium4.9fixed in 8.14.0
Jul 262024Elasticsearch Insertion of Sensitive Information into Log File
CVE-2023-49921Medium5.2fixed in 7.17.16, 8.11.2
Jul 312024Elasticsearch stores private key on disk unencrypted
CVE-2024-23444Medium4.9fixed in 7.17.23, 8.13.0
Nov 222023Elasticsearch Improper Handling of Exceptional Conditions
CVE-2023-46673Medium6.5fixed in 7.17.14, 8.10.3

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.