vendor:
Elasticsearch
by:
TOUHAMI KASBAOUI
6.1
CVSS
HIGH
Remote Code Execution
94
CWE
Product Name: Elasticsearch
Affected Version From: 8.5.2003
Affected Version To: 8.5.3 / OpenSearch
Patch Exists: NO
Related CWE: CVE-2023-31419
CPE: a:elastic:elasticsearch:8.5.3
Platforms Tested: Ubuntu 20.04 LTS
2023
Elasticsearch CVE-2023-31419 Remote Code Execution
The exploit allows an attacker to execute arbitrary code remotely on Elasticsearch versions 8.5.3 and OpenSearch. By sending a crafted payload, an attacker can perform this remote code execution. This exploit is associated with CVE-2023-31419.
Mitigation:
To mitigate this vulnerability, it is recommended to update Elasticsearch to a patched version as soon as the fix is available. Additionally, restrict network access to Elasticsearch servers to trusted sources only.