Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2023-46674

Опубликовано: 05 дек. 2023
Источник: nvd
CVSS3: 6
CVSS3: 7.8
EPSS Низкий

Описание

An issue was identified that allowed the unsafe deserialization of java objects from hadoop or spark configuration properties that could have been modified by authenticated users. Elastic would like to thank Yakov Shafranovich, with Amazon Web Services for reporting this issue.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:elastic:elasticsearch:*:*:*:*:*:*:*:*
Версия до 7.17.11 (исключая)
cpe:2.3:a:elastic:elasticsearch:*:*:*:*:*:*:*:*
Версия от 8.0.0 (включая) до 8.9.0 (исключая)

EPSS

Процентиль: 20%
0.00064
Низкий

6 Medium

CVSS3

7.8 High

CVSS3

Дефекты

CWE-502
CWE-502

Связанные уязвимости

CVSS3: 6
redhat
около 2 лет назад

An issue was identified that allowed the unsafe deserialization of java objects from hadoop or spark configuration properties that could have been modified by authenticated users. Elastic would like to thank Yakov Shafranovich, with Amazon Web Services for reporting this issue.

CVSS3: 6
github
около 2 лет назад

Elasticsearch-hadoop Unsafe Deserialization

EPSS

Процентиль: 20%
0.00064
Низкий

6 Medium

CVSS3

7.8 High

CVSS3

Дефекты

CWE-502
CWE-502