Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-rv74-m283-5j95

Опубликовано: 05 дек. 2023
Источник: github
Github: Прошло ревью
CVSS3: 6

Описание

Elasticsearch-hadoop Unsafe Deserialization

An issue was identified that allowed the unsafe deserialization of java objects from hadoop or spark configuration properties that could have been modified by authenticated users. Elastic would like to thank Yakov Shafranovich, with Amazon Web Services for reporting this issue.

Пакеты

Наименование

org.elasticsearch:elasticsearch-hadoop

maven
Затронутые версииВерсия исправления

< 7.17.11

7.17.11

Наименование

org.elasticsearch:elasticsearch-hadoop

maven
Затронутые версииВерсия исправления

>= 8.0.0, < 8.9.0

8.9.0

EPSS

Процентиль: 20%
0.00064
Низкий

6 Medium

CVSS3

Дефекты

CWE-502

Связанные уязвимости

CVSS3: 6
redhat
около 2 лет назад

An issue was identified that allowed the unsafe deserialization of java objects from hadoop or spark configuration properties that could have been modified by authenticated users. Elastic would like to thank Yakov Shafranovich, with Amazon Web Services for reporting this issue.

CVSS3: 6
nvd
около 2 лет назад

An issue was identified that allowed the unsafe deserialization of java objects from hadoop or spark configuration properties that could have been modified by authenticated users. Elastic would like to thank Yakov Shafranovich, with Amazon Web Services for reporting this issue.

EPSS

Процентиль: 20%
0.00064
Низкий

6 Medium

CVSS3

Дефекты

CWE-502