vendor:
Elasticsearch
by:
TOUHAMI KASBAOUI
6.1
CVSS
HIGH
Remote Code Execution
20
CWE
Product Name: Elasticsearch
Affected Version From: 37749
Affected Version To: 8.5.3 / OpenSearch
Patch Exists: NO
Related CWE: CVE-2023-31419
CPE: a:elastic:elasticsearch:8.5.3
Platforms Tested: Ubuntu 20.04 LTS
2023
Elasticsearch Remote Code Execution Vulnerability
The exploit allows an attacker to execute remote code on Elasticsearch versions 8.5.3 and OpenSearch. By sending a crafted payload within a search query, an attacker can trigger the vulnerability. This exploit is linked to CVE-2023-31419.
Mitigation:
To mitigate this vulnerability, it is recommended to update Elasticsearch to a patched version. Additionally, restrict access to the Elasticsearch server to trusted users only.