Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-pw39-f3m5-cxfc

Опубликовано: 29 мар. 2024
Источник: github
Github: Прошло ревью
CVSS3: 4.3

Описание

Elasticsearch Uncaught Exception leading to crash

An uncaught exception in Elasticsearch >= 8.4.0 and < 8.11.1 occurs when an encrypted PDF is passed to an attachment processor through the REST API. The Elasticsearch ingest node that attempts to parse the PDF file will crash. This does not happen with password-protected PDF files or with unencrypted PDF files.

Пакеты

Наименование

org.elasticsearch:elasticsearch

maven
Затронутые версииВерсия исправления

>= 8.4.0, < 8.11.1

8.11.1

EPSS

Процентиль: 14%
0.00047
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-248

Связанные уязвимости

CVSS3: 4.3
ubuntu
почти 2 года назад

An uncaught exception in Elasticsearch >= 8.4.0 and < 8.11.1 occurs when an encrypted PDF is passed to an attachment processor through the REST API. The Elasticsearch ingest node that attempts to parse the PDF file will crash. This does not happen with password-protected PDF files or with unencrypted PDF files.

CVSS3: 4.3
redhat
почти 2 года назад

An uncaught exception in Elasticsearch >= 8.4.0 and < 8.11.1 occurs when an encrypted PDF is passed to an attachment processor through the REST API. The Elasticsearch ingest node that attempts to parse the PDF file will crash. This does not happen with password-protected PDF files or with unencrypted PDF files.

CVSS3: 4.3
nvd
почти 2 года назад

An uncaught exception in Elasticsearch >= 8.4.0 and < 8.11.1 occurs when an encrypted PDF is passed to an attachment processor through the REST API. The Elasticsearch ingest node that attempts to parse the PDF file will crash. This does not happen with password-protected PDF files or with unencrypted PDF files.

CVSS3: 4.3
debian
почти 2 года назад

An uncaught exception in Elasticsearch >= 8.4.0 and < 8.11.1 occurs wh ...

CVSS3: 4.3
fstec
почти 2 года назад

Уязвимость реализации прикладного программного интерфейса поисковой системы Elasticsearch, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 14%
0.00047
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-248