Skip to content
ElasticsearchGHSA-qwrx-45xf-jjf7

Elasticsearch vulnerable to stack overflow in the search API

Medium6.5CVE-2023-31419 · Published Oct 26, 2023 · updated Feb 22, 2024

GitHub advisory

Affected versions

PackageAffectedFixed in
org.elasticsearch:elasticsearch
Maven
>= 7.0.0, < 7.17.137.17.13
>= 8.0.0, < 8.9.18.9.1
Details and references

A flaw was discovered in Elasticsearch affecting the `_search` API that allowed a specially crafted query string to cause a stack overflow and ultimately a denial of service.

CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Severity from
GitHub (reviewed advisory)
Weakness
CWE-121, CWE-787
Also known as
BIT-elasticsearch-2023-31419, CVE-2023-31419

More Elasticsearch advisories

All Elasticsearch
DateAdvisory
Oct 262023Elasticsearch vulnerable to Uncontrolled Resource Consumption
CVE-2023-31418High7.5fixed in 7.17.13, 8.9.0
Oct 262023Elasticsearch allows insertion of sensitive information into log files when using deprecated URIs
CVE-2023-31417Medium4.1fixed in 7.17.13, 8.9.2
Nov 222023Elasticsearch Improper Handling of Exceptional Conditions
CVE-2023-46673Medium6.5fixed in 7.17.14, 8.10.3
Mar 272024Elasticsearch Uncontrolled Resource Consumption vulnerability
CVE-2024-23450Medium4.9fixed in 7.17.19, 8.13.0
Mar 272024Elasticsearch Incorrect Authorization vulnerability
CVE-2024-23451Medium4.4fixed in 8.13.0
Mar 292024Elasticsearch Uncaught Exception leading to crash
CVE-2024-23449Medium4.3fixed in 8.11.1

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.