QID 996288
Date Published: 2023-12-14
QID 996288: Java (Maven) Security Update for org.elasticsearch:elasticsearch-hadoop (GHSA-rv74-m283-5j95)
An issue was identified that allowed the unsafe deserialization of java objects from hadoop or spark configuration properties that could have been modified by authenticated users. Elastic would like to thank Yakov Shafranovich, with Amazon Web Services for reporting this issue.
Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.
Solution
Refer to Github security advisory GHSA-rv74-m283-5j95 for updates and patch information.
Vendor References
- GHSA-rv74-m283-5j95 -
github.com/advisories/GHSA-rv74-m283-5j95
CVEs related to QID 996288
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-rv74-m283-5j95 | org.elasticsearch:elasticsearch-hadoop |
|