CVE-2024-23450
Description
A flaw was discovered in Elasticsearch, where processing a document in a deeply nested pipeline on an ingest node could cause the Elasticsearch node to crash.
CWE
- CWE-400 — CWE-400 Uncontrolled Resource Consumption
Affected
- Elastic / Elasticsearch — v=7.0.0 <7.17.19 [affected]; v=8.0.0 <8.13.0 [affected]
CVSS
- 3.1 score=4.9 severity=MEDIUM
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H
References
- https://discuss.elastic.co/t/elasticsearch-8-13-0-7-17-19-security-update-esa-2024-06/356314
- https://www.elastic.co/community/security
- https://security.netapp.com/advisory/ntap-20240517-0010/
Source
cvelistV5-main/cves/2024/23xxx/CVE-2024-23450.json