HIGH✓ PATCH🇬🇧 English

CVE-2023-31418

CVSS 7.5v3.1pub. 2023-10-26upd. 2024-11-21

An issue has been identified with how Elasticsearch handled incoming requests on the HTTP layer. An unauthenticated user could force an Elasticsearch node to exit with an OutOfMemory error by sending a moderate number of malformed HTTP requests. The issue was identified by Elastic Engineering and we have no indication that the issue is known or that it is being exploited in the wild.

oryginał EN
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
  • Elastic Cloud Enterprise

    APP
    Elastic
    3.6.0≤ 2.13.3
  • Elastic Elasticsearch

    APP
    Elastic
    ≤ 7.17.128.0.0 – 8.8.2
🟢
PATCH DOSTĘPNY
Aktualizacja od producenta gotowa. Wdrożenie w ramach standardowego cyklu.
CWE
Referencje

Powiązane podatności

CVE-2015-1427CRITICAL9.8⚠ KEVPL ✓ten sam produkt

Elasticsearch: ucieczka z sandboksa Groovy i zdalne wykonanie poleceń

CVE-2025-37729CRITICAL9.1PL ✓ten sam produkt

Elastic Cloud Enterprise — Server-Side Template Injection (SSTI) w silniku Jinjava

CVE-2015-5377CRITICAL9.8PL ✓ten sam produkt

RCE w Elasticsearch przez protokół transportowy (przed wersją 1.6.1)

CVE-2014-3120HIGH8.1⚠ KEVten sam produkt

The default configuration in Elasticsearch before 1.2 enables dynamic scripting, which allows remote attackers...

CVE-2026-72649HIGH8.8ten sam produkt

Deserialization of Untrusted Data (CWE-502) in the Elasticsearch machine learning component can lead to remote...