CVE-2023-31418
Summary
| CVE | CVE-2023-31418 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-10-26 18:15:00 UTC |
| Updated | 2023-11-30 22:15:00 UTC |
| Description | An issue has been identified with how Elasticsearch handled incoming requests on the HTTP layer. An unauthenticated user could force an Elasticsearch node to exit with an OutOfMemory error by sending a moderate number of malformed HTTP requests. The issue was identified by Elastic Engineering and we have no indication that the issue is known or that it is being exploited in the wild. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| security.netapp.com/advisory/ntap-20231130-0005 |
|
security.netapp.com |
|
| www.elastic.co/community/security |
MISC |
www.elastic.co |
|
| Elasticsearch 8.9.0, 7.17.13 Security Update - Security Announcements - Discuss the Elastic Stack |
MISC |
discuss.elastic.co |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 995771 Java (Maven) Security Update for org.elasticsearch:elasticsearch (GHSA-2cqf-6xv9-f22w)