CVE-2024-23449Uncaught Exception in Elasticsearch

CWE-248Uncaught Exception6 documents5 sources
Severity
5.3MEDIUMNVD
CNA4.3
EPSS
0.0%
top 85.64%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMar 29

Description

An uncaught exception in Elasticsearch >= 8.4.0 and < 8.11.1 occurs when an encrypted PDF is passed to an attachment processor through the REST API. The Elasticsearch ingest node that attempts to parse the PDF file will crash. This does not happen with password-protected PDF files or with unencrypted PDF files.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:LExploitability: 3.9 | Impact: 1.4

Affected Packages2 packages

CVEListV5elastic/elasticsearch8.4.08.11.1
NVDelastic/elasticsearch8.4.08.11.1

🔴Vulnerability Details

4
OSV
CVE-2024-23449: An uncaught exception in Elasticsearch >= 82024-03-29
OSV
Elasticsearch Uncaught Exception leading to crash2024-03-29
CVEList
Elasticsearch Uncaught Exception2024-03-29
GHSA
Elasticsearch Uncaught Exception leading to crash2024-03-29

📋Vendor Advisories

1
Red Hat
elasticsearch: uncaught exception leads to crash2024-03-29
CVE-2024-23449 — Uncaught Exception in Elastic | cvebase