Back to Vulnerability Directory
HIGHFixed upstream

CVE-2023-31418

Elasticsearch: unauthenticated malformed HTTP requests cause OutOfMemory

Technology

Elasticsearch

CVSS Score

7.5 / 10.0

Affected Versions

Up to 7.17.12; 8.0.0 to 8.8.2

Upstream Fix

7.17.13; 8.9.0

Published

October 26, 2023

OSSeva Coverage

Fixed upstream

Description

An issue in how Elasticsearch handled incoming requests on the HTTP layer let an unauthenticated user force a node to exit with an OutOfMemory error by sending a moderate number of malformed HTTP requests. Fixed in 7.17.13 and 8.9.0.

Upstream record: NVD · CVE.org

Is your Elasticsearch deployment affected?

If you're running Up to 7.17.12; 8.0.0 to 8.8.2, you need this patch. Book a discovery call to get covered.