Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2023-31418

Опубликовано: 26 окт. 2023
Источник: nvd
CVSS3: 7.5
EPSS Низкий

Описание

An issue has been identified with how Elasticsearch handled incoming requests on the HTTP layer. An unauthenticated user could force an Elasticsearch node to exit with an OutOfMemory error by sending a moderate number of malformed HTTP requests. The issue was identified by Elastic Engineering and we have no indication that the issue is known or that it is being exploited in the wild.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:elastic:elasticsearch:*:*:*:*:*:*:*:*
Версия до 7.17.12 (включая)
cpe:2.3:a:elastic:elasticsearch:*:*:*:*:*:*:*:*
Версия от 8.0.0 (включая) до 8.8.2 (включая)
Конфигурация 2

Одно из

cpe:2.3:a:elastic:elastic_cloud_enterprise:*:*:*:*:*:*:*:*
Версия до 2.13.3 (включая)
cpe:2.3:a:elastic:elastic_cloud_enterprise:3.6.0:*:*:*:*:*:*:*

EPSS

Процентиль: 67%
0.00549
Низкий

7.5 High

CVSS3

Дефекты

CWE-400
CWE-400

Связанные уязвимости

CVSS3: 7.5
ubuntu
почти 2 года назад

An issue has been identified with how Elasticsearch handled incoming requests on the HTTP layer. An unauthenticated user could force an Elasticsearch node to exit with an OutOfMemory error by sending a moderate number of malformed HTTP requests. The issue was identified by Elastic Engineering and we have no indication that the issue is known or that it is being exploited in the wild.

CVSS3: 7.5
redhat
почти 2 года назад

An issue has been identified with how Elasticsearch handled incoming requests on the HTTP layer. An unauthenticated user could force an Elasticsearch node to exit with an OutOfMemory error by sending a moderate number of malformed HTTP requests. The issue was identified by Elastic Engineering and we have no indication that the issue is known or that it is being exploited in the wild.

CVSS3: 7.5
debian
почти 2 года назад

An issue has been identified with how Elasticsearch handled incoming r ...

CVSS3: 7.5
github
почти 2 года назад

Elasticsearch vulnerable to Uncontrolled Resource Consumption

CVSS3: 7.5
fstec
почти 2 года назад

Уязвимость поисковой системы Elasticsearch, связанная с неконтролируемым расходом ресурсов, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 67%
0.00549
Низкий

7.5 High

CVSS3

Дефекты

CWE-400
CWE-400