Description
It was identified that malformed scripts used in the script processor of an Ingest Pipeline could cause an Elasticsearch node to crash when calling the Simulate Pipeline API.
Remediation
References
https://discuss.elastic.co/t/elasticsearch-7-17-14-8-10-3-security-update-esa-2023-24/347708
https://www.elastic.co/community/security
Related Vulnerabilities
CVE-2011-2204 Vulnerability in maven package org.apache.tomcat:tomcat-catalina
CVE-2023-4303 Vulnerability in maven package org.jenkins-ci.plugins:fortify
CVE-2017-12623 Vulnerability in maven package org.apache.nifi:nifi-security-utils
CVE-2020-7011 Vulnerability in npm package @elastic/app-search-javascript
CVE-2021-21120 Vulnerability in maven package org.webjars.npm:electron