elasticsearch: Improper Handling of Exceptional Conditions
Published Nov 22, 2023
7.5
HIGHCVSS 3.1
EPSS 0.84%
Description
It was identified that malformed scripts used in the script processor of an Ingest Pipeline could cause an Elasticsearch node to crash when calling the Simulate Pipeline API.
Affected products
-
- Version 7.0.0StatusaffectedConstraints<7.17.14
- Version 8.0.0StatusaffectedConstraints<8.10.3
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Elastic | Elasticsearch | unaffected |
|
- ≥ 7.0.0 · < 7.17.14
- ≥ 8.0.0 · < 8.10.3
No data.
Logging Subsystem for Red Hat OpenShift
elasticsearch6-container
Not affected
Logging Subsystem for Red Hat OpenShift
openshift-logging/elasticsearch-rhel8-operator
Not affected
Red Hat Quay 3
quay/quay-rhel8
Affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Logging Subsystem for Red Hat OpenShift | elasticsearch6-container | Not affected | n/a |
| Logging Subsystem for Red Hat OpenShift | openshift-logging/elasticsearch-rhel8-operator | Not affected | n/a |
| Red Hat Quay 3 | quay/quay-rhel8 | Affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
Red Hat rates this as a moderate impact, as this issue could only be triggered if a malicious user is pre-authenticated in order to process a script via Ingest Pipeline.
Red Hat mitigation
No mitigation is yet available for this flaw.
References (7)
- https://access.redhat.com/security/cve/CVE-2023-46673 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2251123 Issue Tracking
- https://discuss.elastic.co/t/elasticsearch-7-17-14-8-10-3-security-update-esa-2023-24/347708 Vendor Advisory
- https://github.com/advisories/GHSA-285m-vhfq-xx4h Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2023-46673
- https://www.cve.org/CVERecord?id=CVE-2023-46673
- https://www.elastic.co/community/security Vendor Advisory
Change history (0)
No recorded changes yet.