Database/Control plane, storage & DevOps
Elasticsearch: Crafted _search query string
CVSS 6.5CVE-2023-31419Control plane, storage & DevOpscurated
Impact
Crafted _search query string -> stack overflow and node denial of service
Who can reach it
Network (remote)
What to do
Control-plane: rolling upgrade of the log cluster
References
Related entries
- Elasticsearch: elasticsearch-certutil --csr writes the private key to disk unencrypted despite --passCVE-2024-23444 · ElasticsearchMedium
- Argo CD: repo-server extracts a user-controlled tar.gz without size validationCVE-2023-40584 · Argo CDMedium
- Samba: SMB client can truncate files despite read-only permissions when acl_xattr ignores system ACLsCVE-2023-4091 · SambaMedium
- Ceph RGW (IBM Spectrum Fusion HCI): Improper bucket access lets an actor perform unauthorized actions in RGWCVE-2023-43040 · Ceph RGW (IBM Spectrum Fusion HCI)Medium
- Keycloak: Regex complexity in SearchQueryUtilsCVE-2024-10270 · KeycloakMedium
- Intel Data Center GPU Max Series 1100 / 1550: A second improper conditions check in the Max Series allowingCVE-2024-24580 · Intel Data Center GPU Max Series 1100 / 1550Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.