Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2023-46673

Опубликовано: 22 нояб. 2023
Источник: redhat
CVSS3: 7.5

Описание

It was identified that malformed scripts used in the script processor of an Ingest Pipeline could cause an Elasticsearch node to crash when calling the Simulate Pipeline API.

A flaw was found in Elasticsearch. A malicious script used in the script processor of an Ingest Pipeline could cause an Elasticsearch node to crash when calling the Simulate Pipeline API.

Отчет

Red Hat rates this as a moderate impact, as this issue could only be triggered if a malicious user is pre-authenticated in order to process a script via Ingest Pipeline.

Меры по смягчению последствий

No mitigation is yet available for this flaw.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Logging Subsystem for Red Hat OpenShiftelasticsearch6-containerNot affected
Logging Subsystem for Red Hat OpenShiftopenshift-logging/elasticsearch-rhel8-operatorNot affected
Red Hat Quay 3quay/quay-rhel8Affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-755
https://bugzilla.redhat.com/show_bug.cgi?id=2251123elasticsearch: Improper Handling of Exceptional Conditions

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 6.5
ubuntu
около 2 лет назад

It was identified that malformed scripts used in the script processor of an Ingest Pipeline could cause an Elasticsearch node to crash when calling the Simulate Pipeline API.

CVSS3: 6.5
nvd
около 2 лет назад

It was identified that malformed scripts used in the script processor of an Ingest Pipeline could cause an Elasticsearch node to crash when calling the Simulate Pipeline API.

CVSS3: 6.5
debian
около 2 лет назад

It was identified that malformed scripts used in the script processor ...

CVSS3: 6.5
github
около 2 лет назад

Elasticsearch Improper Handling of Exceptional Conditions

7.5 High

CVSS3