HIGH✓ PATCH🇵🇱 Wersja polska

CVE-2023-31418

CVSS 7.5v3.1pub. 2023-10-26upd. 2024-11-21

An issue has been identified with how Elasticsearch handled incoming requests on the HTTP layer. An unauthenticated user could force an Elasticsearch node to exit with an OutOfMemory error by sending a moderate number of malformed HTTP requests. The issue was identified by Elastic Engineering and we have no indication that the issue is known or that it is being exploited in the wild.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
  • Elastic Cloud Enterprise

    APP
    Elastic
    3.6.0≤ 2.13.3
  • Elastic Elasticsearch

    APP
    Elastic
    ≤ 7.17.128.0.0 – 8.8.2
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
CWE
References

Related vulnerabilities

CVE-2015-1427CRITICAL9.8⚠ KEVPL ✓same product

Elasticsearch: ucieczka z sandboksa Groovy i zdalne wykonanie poleceń

CVE-2025-37729CRITICAL9.1PL ✓same product

Elastic Cloud Enterprise — Server-Side Template Injection (SSTI) w silniku Jinjava

CVE-2015-5377CRITICAL9.8PL ✓same product

RCE w Elasticsearch przez protokół transportowy (przed wersją 1.6.1)

CVE-2014-3120HIGH8.1⚠ KEVsame product

The default configuration in Elasticsearch before 1.2 enables dynamic scripting, which allows remote attackers...

CVE-2026-72649HIGH8.8same product

Deserialization of Untrusted Data (CWE-502) in the Elasticsearch machine learning component can lead to remote...