Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2024-23449

Опубликовано: 29 мар. 2024
Источник: ubuntu
Приоритет: medium
CVSS3: 4.3

Описание

An uncaught exception in Elasticsearch >= 8.4.0 and < 8.11.1 occurs when an encrypted PDF is passed to an attachment processor through the REST API. The Elasticsearch ingest node that attempts to parse the PDF file will crash. This does not happen with password-protected PDF files or with unencrypted PDF files.

РелизСтатусПримечание
devel

DNE

esm-apps-legacy/xenial

needs-triage

esm-apps/xenial

ignored

end of ESM support, was needs-triage
esm-infra/focal

DNE

focal

DNE

jammy

DNE

mantic

DNE

noble

DNE

oracular

DNE

plucky

DNE

Показывать по

4.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 4.3
redhat
больше 2 лет назад

An uncaught exception in Elasticsearch >= 8.4.0 and < 8.11.1 occurs when an encrypted PDF is passed to an attachment processor through the REST API. The Elasticsearch ingest node that attempts to parse the PDF file will crash. This does not happen with password-protected PDF files or with unencrypted PDF files.

CVSS3: 4.3
nvd
больше 2 лет назад

An uncaught exception in Elasticsearch >= 8.4.0 and < 8.11.1 occurs when an encrypted PDF is passed to an attachment processor through the REST API. The Elasticsearch ingest node that attempts to parse the PDF file will crash. This does not happen with password-protected PDF files or with unencrypted PDF files.

CVSS3: 4.3
debian
больше 2 лет назад

An uncaught exception in Elasticsearch >= 8.4.0 and < 8.11.1 occurs wh ...

CVSS3: 4.3
github
больше 2 лет назад

Elasticsearch Uncaught Exception leading to crash

CVSS3: 4.3
fstec
больше 2 лет назад

Уязвимость реализации прикладного программного интерфейса поисковой системы Elasticsearch, позволяющая нарушителю вызвать отказ в обслуживании

4.3 Medium

CVSS3