QID 996022

Date Published: 2023-11-23

QID 996022: Java (Maven) Security Update for org.elasticsearch:elasticsearch (GHSA-285m-vhfq-xx4h)

It was identified that malformed scripts used in the script processor of an Ingest Pipeline could cause an Elasticsearch node to crash when calling the Simulate Pipeline API.

Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.

  • CVSS V3 rated as High - 7.5 severity.
  • CVSS V2 rated as Medium - 5.4 severity.
  • Solution
    Refer to Github security advisory GHSA-285m-vhfq-xx4h for updates and patch information.
    Vendor References

    CVEs related to QID 996022

    Software Advisories
    Advisory ID Software Component Link
    GHSA-285m-vhfq-xx4h org.elasticsearch:elasticsearch URL Logo github.com/advisories/GHSA-285m-vhfq-xx4h