Back

HIGH

elasticsearch: Improper Handling of Exceptional Conditions

Published Nov 22, 2023

Description

It was identified that malformed scripts used in the script processor of an Ingest Pipeline could cause an Elasticsearch node to crash when calling the Simulate Pipeline API.

Affected products

Remediation

Red Hat statement

Red Hat rates this as a moderate impact, as this issue could only be triggered if a malicious user is pre-authenticated in order to process a script via Ingest Pipeline.

Red Hat mitigation

No mitigation is yet available for this flaw.

Weaknesses (1)

References (7)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner elastic
Published Nov 22, 2023
Updated Aug 2, 2024
Reserved Oct 24, 2023
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Nov 22, 2023
GHSA-285M-VHFQ-XX4H