Elasticsearch Uncontrolled Resource Consumption vulnerability (ESA-2024-06)
A flaw was discovered in Elasticsearch, where processing a document in a deeply nested pipeline on an ingest node could cause the Elasticsearch node to crash.
Affected Versions:
Elasticsearch versions on or after 7.0.0 and before 7.17.19
Elasticsearch versions on or after 8.0.0 and before 8.13.0
Solutions and Mitigations:
The issue is resolved in versions 8.13.0 and 7.17.19.
Severity: CVSSv3: 4.9(Medium) CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H
CVE ID: CVE-2024-23450