PT-2023-6895 · Elastic · Elasticsearch

CVE-2023-31418

·

Publicado

2023-10-26

·

Atualizado

2024-03-06

CVSS v2.0

7.8

Alta

VetorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Elasticsearch (affected versions not specified)
Description The issue is related to how Elasticsearch handles incoming requests on the HTTP layer. An unauthenticated user could force an Elasticsearch node to exit with an OutOfMemory error by sending a moderate number of malformed HTTP requests. There is no indication that the issue is known or that it is being exploited in the wild.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

DoS

Resource Exhaustion

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2023-07913
BIT-ELASTICSEARCH-2023-31418
CVE-2023-31418
GHSA-2CQF-6XV9-F22W

Produtos afetados

Elasticsearch