7.5
CVE-2023-46673
- EPSS 0.43%
- Published 22.11.2023 10:15:08
- Last modified 21.11.2024 08:29:02
- Source bressers@elastic.co
- Teams watchlist Login
- Open Login
It was identified that malformed scripts used in the script processor of an Ingest Pipeline could cause an Elasticsearch node to crash when calling the Simulate Pipeline API.
Data is provided by the National Vulnerability Database (NVD)
Elastic ≫ Elasticsearch Version >= 7.0.0 < 7.17.14
Elastic ≫ Elasticsearch Version >= 8.0.0 < 8.10.3
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Type | Source | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.43% | 0.62 |
Source | Base Score | Exploit Score | Impact Score | Vector string |
---|---|---|---|---|
nvd@nist.gov | 7.5 | 3.9 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
|
bressers@elastic.co | 6.5 | 2.8 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
|
CWE-755 Improper Handling of Exceptional Conditions
The product does not handle or incorrectly handles an exceptional condition.