Elasticsearch 8.13.0 / 7.17.19 Security Update (ESA-2024-06)

Elasticsearch Uncontrolled Resource Consumption vulnerability (ESA-2024-06)

A flaw was discovered in Elasticsearch, where processing a document in a deeply nested pipeline on an ingest node could cause the Elasticsearch node to crash.

Affected Versions:
Elasticsearch versions on or after 7.0.0 and before 7.17.19
Elasticsearch versions on or after 8.0.0 and before 8.13.0

Solutions and Mitigations:
The issue is resolved in versions 8.13.0 and 7.17.19.

Severity: CVSSv3: 4.9(Medium) CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H

CVE ID: CVE-2024-23450