A flaw was discovered in Elasticsearch, affecting the _search API that allowed a specially crafted query string to cause a Stack Overflow and ultimately a Denial of Service.
References
Link | Resource |
---|---|
https://discuss.elastic.co/t/elasticsearch-8-9-1-7-17-13-security-update/343297 | Vendor Advisory |
https://security.netapp.com/advisory/ntap-20231116-0010/ | Third Party Advisory |
https://www.elastic.co/community/security | Vendor Advisory |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: elastic
Published: 2023-10-26T17:06:14.305Z
Updated: 2023-10-26T18:49:20.424Z
Reserved: 2023-04-27T18:54:56.704Z
Link: CVE-2023-31419
JSON object: View
NVD Information
Status : Analyzed
Published: 2023-10-26T18:15:08.647
Modified: 2024-02-01T02:16:30.827
Link: CVE-2023-31419
JSON object: View
Redhat Information
No data.