ElasticsearchGHSA-qwrx-45xf-jjf7
Elasticsearch vulnerable to stack overflow in the search API
Medium6.5CVE-2023-31419 · Published Oct 26, 2023 · updated Feb 22, 2024
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| org.elasticsearch:elasticsearch Maven | >= 7.0.0, < 7.17.13 | 7.17.13 |
| >= 8.0.0, < 8.9.1 | 8.9.1 |
Details and references
A flaw was discovered in Elasticsearch affecting the `_search` API that allowed a specially crafted query string to cause a stack overflow and ultimately a denial of service.
More Elasticsearch advisories
All Elasticsearch| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Oct 262023 | Elasticsearch vulnerable to Uncontrolled Resource Consumption CVE-2023-31418High7.5fixed in 7.17.13, 8.9.0 | High7.5 | 7.17.13, 8.9.0 |
| Oct 262023 | Elasticsearch allows insertion of sensitive information into log files when using deprecated URIs CVE-2023-31417Medium4.1fixed in 7.17.13, 8.9.2 | Medium4.1 | 7.17.13, 8.9.2 |
| Nov 222023 | Elasticsearch Improper Handling of Exceptional Conditions CVE-2023-46673Medium6.5fixed in 7.17.14, 8.10.3 | Medium6.5 | 7.17.14, 8.10.3 |
| Mar 272024 | Elasticsearch Uncontrolled Resource Consumption vulnerability CVE-2024-23450Medium4.9fixed in 7.17.19, 8.13.0 | Medium4.9 | 7.17.19, 8.13.0 |
| Mar 272024 | Elasticsearch Incorrect Authorization vulnerability CVE-2024-23451Medium4.4fixed in 8.13.0 | Medium4.4 | 8.13.0 |
| Mar 292024 | Elasticsearch Uncaught Exception leading to crash CVE-2024-23449Medium4.3fixed in 8.11.1 | Medium4.3 | 8.11.1 |