NA

CVE-2023-31418

Published: 26/10/2023 Updated: 30/11/2023
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 0

Vulnerability Summary

An issue has been identified with how Elasticsearch handled incoming requests on the HTTP layer. An unauthenticated user could force an Elasticsearch node to exit with an OutOfMemory error by sending a moderate number of malformed HTTP requests. The issue was identified by Elastic Engineering and we have no indication that the issue is known or that it is being exploited in the wild.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

elastic elasticsearch

elastic elastic cloud enterprise

elastic elastic cloud enterprise 3.6.0

Vendor Advisories

Description<!---->An issue has been identified with how Elasticsearch handled incoming requests on the HTTP layer This flaw allows an unauthenticated user to force an Elasticsearch node to exit with an OutOfMemory error by sending a moderate number of malformed HTTP requestsAn issue has been identified with how Elasticsearch handled incoming requ ...