Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2024-23449

Опубликовано: 29 мар. 2024
Источник: nvd
CVSS3: 4.3
CVSS3: 5.3
EPSS Низкий

Описание

An uncaught exception in Elasticsearch >= 8.4.0 and < 8.11.1 occurs when an encrypted PDF is passed to an attachment processor through the REST API. The Elasticsearch ingest node that attempts to parse the PDF file will crash. This does not happen with password-protected PDF files or with unencrypted PDF files.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:elastic:elasticsearch:*:*:*:*:*:*:*:*
Версия от 8.4.0 (включая) до 8.11.1 (исключая)

EPSS

Процентиль: 50%
0.00681
Низкий

4.3 Medium

CVSS3

5.3 Medium

CVSS3

Дефекты

CWE-248
NVD-CWE-Other

Связанные уязвимости

CVSS3: 4.3
ubuntu
больше 2 лет назад

An uncaught exception in Elasticsearch >= 8.4.0 and < 8.11.1 occurs when an encrypted PDF is passed to an attachment processor through the REST API. The Elasticsearch ingest node that attempts to parse the PDF file will crash. This does not happen with password-protected PDF files or with unencrypted PDF files.

CVSS3: 4.3
redhat
больше 2 лет назад

An uncaught exception in Elasticsearch >= 8.4.0 and < 8.11.1 occurs when an encrypted PDF is passed to an attachment processor through the REST API. The Elasticsearch ingest node that attempts to parse the PDF file will crash. This does not happen with password-protected PDF files or with unencrypted PDF files.

CVSS3: 4.3
debian
больше 2 лет назад

An uncaught exception in Elasticsearch >= 8.4.0 and < 8.11.1 occurs wh ...

CVSS3: 4.3
github
больше 2 лет назад

Elasticsearch Uncaught Exception leading to crash

CVSS3: 4.3
fstec
больше 2 лет назад

Уязвимость реализации прикладного программного интерфейса поисковой системы Elasticsearch, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 50%
0.00681
Низкий

4.3 Medium

CVSS3

5.3 Medium

CVSS3

Дефекты

CWE-248
NVD-CWE-Other