QID 730939
Date Published: 2023-10-18
QID 730939: Elasticsearch StackOverflow Vulnerability (ESA-2023-14)
Elasticsearch is a search server based on Lucene that provides a distributed, multitenant-capable full-text search engine with an HTTP web interface and schema-free JSON documents.
A flaw was discovered in Elasticsearch, affecting the _search API that allowed a specially crafted query string to cause a Stack Overflow and ultimately a Denial of Service.
Affected Versions:
Elasticsearch versions from 7.0.0 prior to 7.17.13
Elasticsearch versions from 8.0.0 prior to 8.9.1
QID detection logic:
Checks the vulnerable versions of ElasticSearch.
Successful exploitation of this vulnerability may allow cause a Stack Overflow and ultimately a Denial of Service
Solution
Customers are advised to refer Elasticsearch advisory for more details
Vendor References
CVEs related to QID 730939
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| ESA-2023-14 |
|