Elasticsearch vulnerable to Uncontrolled Resource Consumption
GHSA-2cqf-6xv9-f22w · BIT-elasticsearch-2023-31418 · CVE-2023-31418
Published · Modified
AI SAST
Find this class of vulnerability in your own code
Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.
Description
An issue has been identified with how Elasticsearch handled incoming requests on the HTTP layer. An unauthenticated user could force an Elasticsearch node to exit with an OutOfMemory error by sending a moderate number of malformed HTTP requests. The issue was identified by Elastic Engineering and we have no indication that the issue is known or that it is being exploited in the wild.
Ready to move
Start Securing
Free, no credit card | First findings in minutes