Vulnerability CVE-2023-31419


Published: 2023-10-26

Description:
A flaw was discovered in Elasticsearch, affecting the _search API that allowed a specially crafted query string to cause a Stack Overflow and ultimately a Denial of Service.




See advisories in our WLB2 database:
Topic
Author
Date
High
Elasticsearch 8.5.3 Stack Overflow
Touhami Kasbaoui
24.09.2023

Type:

CWE-119

(Improper Restriction of Operations within the Bounds of a Memory Buffer)

 References:
https://www.elastic.co/community/security
https://discuss.elastic.co/t/elasticsearch-8-9-1-7-17-13-security-update/343297

Copyright 2024, cxsecurity.com

 

Back to Top