Vulnerability detail
Enriched intelligence for a single CVE
High
CVE-2023-31418
PUBLISHEDElasticsearch uncontrolled resource consumption
- Vendor
- Elastic
- Product
- Elasticsearch
- Published
- Oct 26, 2023
- EPSS
- —
Description
An issue has been identified with how Elasticsearch handled incoming requests on the HTTP layer. An unauthenticated user could force an Elasticsearch node to exit with an OutOfMemory error by sending a moderate number of malformed HTTP requests. The issue was identified by Elastic Engineering and we have no indication that the issue is known or that it is being exploited in the wild.
CVSS scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Exploitation status
Exploited in the wild
Recorded 2023-10-26 17:36:42 UTC · Source
Known exploited vulnerability sources
Catalogues that list this CVE as a known exploited vulnerability.
| Source | Added |
|---|---|
| CVE | Oct 26, 2023 |
Timeline
-
CVE ID Reserved
-
CVE Published to Public
-
Added to KEVIntel