Deserialization of Untrusted Data (CWE-502) in the Elasticsearch machine learning component can lead to remote code execution via Object Injection (CAPEC-586). A specially crafted trained model artifact could cause attacker-controlled logic to execute with a materially broader system-call surface than intended. Exploitation requires an authenticated user with sufficient privileges to create and deploy trained models.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HElastic Elasticsearch
APPElastic9.5.08.0.0 – 8.19.20 (excl.)9.0.0 – 9.4.5 (excl.)
Related vulnerabilities
Elasticsearch: ucieczka z sandboksa Groovy i zdalne wykonanie poleceń
RCE w Elasticsearch przez protokół transportowy (przed wersją 1.6.1)
The default configuration in Elasticsearch before 1.2 enables dynamic scripting, which allows remote attackers...
The native inference process that Elasticsearch uses to evaluate uploaded machine learning models accepts a mo...
An issue has been identified with how Elasticsearch handled incoming requests on the HTTP layer. An unauthenti...