Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2024-23450

Опубликовано: 27 мар. 2024
Источник: redhat
CVSS3: 4.9
EPSS Низкий

Описание

A flaw was discovered in Elasticsearch, where processing a document in a deeply nested pipeline on an ingest node could cause the Elasticsearch node to crash.

A flaw was found in elasticsearch. Trying to process a document in a deeply nested pipeline may cause the related ingest node to crash, resulting in a Denial of Service.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Logging Subsystem for Red Hat OpenShiftopenshift-logging/fluentd-rhel9Not affected
Logging Subsystem for Red Hat OpenShiftopenshift-logging/kibana6-rhel8Not affected
Red Hat OpenStack Platform 16.1openstack-pankoNot affected
Red Hat OpenStack Platform 16.2openstack-pankoNot affected
Red Hat Quay 3quay/quay-rhel8Will not fix

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-400
https://bugzilla.redhat.com/show_bug.cgi?id=2271933elasticsearch: Possible denial of service when processing documents in a deeply nested pipeline

EPSS

Процентиль: 58%
0.00951
Низкий

4.9 Medium

CVSS3

Связанные уязвимости

CVSS3: 4.9
ubuntu
больше 2 лет назад

A flaw was discovered in Elasticsearch, where processing a document in a deeply nested pipeline on an ingest node could cause the Elasticsearch node to crash.

CVSS3: 4.9
nvd
больше 2 лет назад

A flaw was discovered in Elasticsearch, where processing a document in a deeply nested pipeline on an ingest node could cause the Elasticsearch node to crash.

msrc
12 дней назад

Elasticsearch Uncontrolled Resource Consumption vulnerability

CVSS3: 4.9
debian
больше 2 лет назад

A flaw was discovered in Elasticsearch, where processing a document in ...

CVSS3: 4.9
github
больше 2 лет назад

Elasticsearch Uncontrolled Resource Consumption vulnerability

EPSS

Процентиль: 58%
0.00951
Низкий

4.9 Medium

CVSS3