# Discuss: Security Vulnerabilities: ESA-2023-14 - CVE-2023-31419

**URL:** <https://discuss.elastic.co/t/discuss-security-vulnerabilities-esa-2023-14-cve-2023-31419/348769>\
**Category:** Elasticsearch\
**Created:** [December 7, 2023, 1:07am UTC](https://discuss.elastic.co/t/discuss-security-vulnerabilities-esa-2023-14-cve-2023-31419/348769 "2023-12-07T01:07:23Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![devkgk](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/devkgk/32/127089_2.png) [@devkgk](https://discuss.elastic.co/u/devkgk)\
**Post date:** [December 7, 2023, 1:07am UTC](https://discuss.elastic.co/t/discuss-security-vulnerabilities-esa-2023-14-cve-2023-31419/348769/1 "2023-12-07T01:07:23Z")

</div>

Hello, everybody.  
According to the community's safety announcement:  
" Elasticsearch StackOverflow vulnerability (ESA-2023-14)

A flaw was discovered in Elasticsearch, affecting the `_search` API that allowed a specially crafted query string to cause a Stack Overflow and ultimately a Denial of Service.

## Affected Versions:

Elasticsearch versions from 7.0.0 to 7.17.12 and from 8.0.0 to 8.9.0

## Solutions and Mitigations:

The issue is resolved in Elasticsearch 7.17.13 and 8.9.1

**CVSSv3:** 6.5 (Medium) - AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H  
**CVE ID:** CVE-2023-31419"

Currently we are on OSS version of Elasticsearch 7.10.2. We are not in a position to upgrade to newer version of Elasticsearch. What could be our option here?

We do not know which issue is associated with this security update or which PR fixed the issue.

Can someone help?

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [December 7, 2023, 1:33am UTC](https://discuss.elastic.co/t/discuss-security-vulnerabilities-esa-2023-14-cve-2023-31419/348769/2 "2023-12-07T01:33:43Z")

</div>

> [@devkgk](#):
>
> Currently we are on OSS version of Elasticsearch 7.10.2. We are not in a position to upgrade to newer version of Elasticsearch. What could be our option here?

Unfortunately I don't there is much to do in this case, 7.10.2 is not supported anymore and will not receive any fix.

> [@devkgk](#):
>
> We do not know which issue is associated with this security update or which PR fixed the issue.

I don't think this information is made public by Elastic, but only someone from Elastic can confirm that.

---

<div class="post-metadata">

**Author:** ![DavidTurner](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/davidturner/32/22453_2.png) [@DavidTurner](https://discuss.elastic.co/u/DavidTurner)\
**Post date:** [December 7, 2023, 8:32am UTC](https://discuss.elastic.co/t/discuss-security-vulnerabilities-esa-2023-14-cve-2023-31419/348769/3 "2023-12-07T08:32:44Z")

</div>

> [@leandrojmp](#):
>
> I don't think this information is made public by Elastic, but only someone from Elastic can confirm that.

That's correct. We can't discuss the details of security vulnerabilities in public, sorry.

> [@devkgk](#):
>
> Currently we are on OSS version of Elasticsearch 7.10.2. We are not in a position to upgrade to newer version of Elasticsearch. What could be our option here?

This version has been EOL (and therefore ineligible for security fixes) for _years_. I'd strongly recommend you re-evaluate your position on upgrades.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 4, 2024, 8:33am UTC](https://discuss.elastic.co/t/discuss-security-vulnerabilities-esa-2023-14-cve-2023-31419/348769/4 "2024-01-04T08:33:20Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
