CVE-2023-31418
Last modified
CVE-2023-31418 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. An issue has been identified with how Elasticsearch handled incoming requests on the HTTP layer. An unauthenticated user could force an Elasticsearch node to exit with an OutOfMemory error by sending a moderate number of malformed HTTP requests. EPSS estimates a 1.23% chance of exploitation in the next 30 days.
Description
An issue has been identified with how Elasticsearch handled incoming requests on the HTTP layer. An unauthenticated user could force an Elasticsearch node to exit with an OutOfMemory error by sending a moderate number of malformed HTTP requests. The issue was identified by Elastic Engineering and we have no indication that the issue is known or that it is being exploited in the wild.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Elastic | Elasticsearch | <= 7.17.12 |
| Elastic | Elasticsearch | >= 8.0.0, <= 8.8.2 |
| Elastic | Elastic Cloud Enterprise | <= 2.13.3 |
| Elastic | Elastic Cloud Enterprise | 3.6.0 |
References
- https://www.elastic.co/community/securityVendor Advisory
- https://www.elastic.co/community/securityVendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2023-31418?
How severe is CVE-2023-31418?
How do I fix CVE-2023-31418?
Are you affected by CVE-2023-31418?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
