Lucene search

K
ubuntucveUbuntu.comUB:CVE-2023-31418
HistoryOct 26, 2023 - 12:00 a.m.

CVE-2023-31418

2023-10-2600:00:00
ubuntu.com
ubuntu.com
7
elasticsearch
http layer
vulnerability
cve-2023-31418
unauthenticated users
outofmemory error
unknown exploitation

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

EPSS

0.001

Percentile

34.7%

An issue has been identified with how Elasticsearch handled incoming
requests on the HTTP layer. An unauthenticated user could force an
Elasticsearch node to exit with an OutOfMemory error by sending a moderate
number of malformed HTTP requests. The issue was identified by Elastic
Engineering and we have no indication that the issue is known or that it is
being exploited in the wild.

OSVersionArchitecturePackageVersionFilename
ubuntu16.04noarchelasticsearch< anyUNKNOWN

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

EPSS

0.001

Percentile

34.7%