vendor:
                    Elasticsearch
                by:
                    TOUHAMI KASBAOUI
                6.1
                        CVSS
                    HIGH
                    Remote Code Execution
                    94
                        CWE
                    Product Name: Elasticsearch
                    Affected Version From:  8.5.2003
                    Affected Version To:  8.5.3 / OpenSearch
                    Patch Exists: NO
                    Related CWE: CVE-2023-31419
                    CPE:  a:elastic:elasticsearch:8.5.3
                    Platforms Tested:  Ubuntu 20.04 LTS
                    2023
                    Elasticsearch CVE-2023-31419 Remote Code Execution
The exploit allows an attacker to execute arbitrary code remotely on Elasticsearch versions 8.5.3 and OpenSearch. By sending a crafted payload, an attacker can perform this remote code execution. This exploit is associated with CVE-2023-31419.
Mitigation:
					To mitigate this vulnerability, it is recommended to update Elasticsearch to a patched version as soon as the fix is available. Additionally, restrict network access to Elasticsearch servers to trusted sources only.