CVE-2024-23449
Elasticsearch Uncaught Exception
Vexday Risk Score
13Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 4.3EPSS 0.7%KEV nãoPoC —Nuclei —Metasploit —Patch —
Lifecycle
29 Mar 2024Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
An uncaught exception in Elasticsearch >= 8.4.0 and < 8.11.1 occurs when an encrypted PDF is passed to an attachment processor through the REST API. The Elasticsearch ingest node that attempts to parse the PDF file will crash. This does not happen with password-protected PDF files or with unencrypted PDF files.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
Affected products
Elastic · ElasticsearchWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →