PT-2023-6895 · Elastic · Elasticsearch

Published

2023-10-26

·

Updated

2024-03-06

·

CVE-2023-31418

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Elasticsearch (affected versions not specified)
Description The issue is related to how Elasticsearch handles incoming requests on the HTTP layer. An unauthenticated user could force an Elasticsearch node to exit with an OutOfMemory error by sending a moderate number of malformed HTTP requests. There is no indication that the issue is known or that it is being exploited in the wild.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Resource Exhaustion

Weakness Enumeration

Related Identifiers

BDU:2023-07913
BIT-ELASTICSEARCH-2023-31418
CVE-2023-31418
GHSA-2CQF-6XV9-F22W

Affected Products

Elasticsearch