Description
It was identified that malformed scripts used in the script processor of an Ingest Pipeline could cause an Elasticsearch node to crash when calling the Simulate Pipeline API.
Remediation
References
https://discuss.elastic.co/t/elasticsearch-7-17-14-8-10-3-security-update-esa-2023-24/347708
https://www.elastic.co/community/security
Related Vulnerabilities
CVE-2021-32050 Vulnerability in maven package org.webjars.npm:mongodb
CVE-2018-17194 Vulnerability in maven package org.apache.nif:nifi-framework-cluster
CVE-2023-46657 Vulnerability in maven package org.jenkins-ci.plugins:gogs-webhook
CVE-2019-10242 Vulnerability in maven package org.eclipse.kura:org.eclipse.kura.web2
CVE-2021-21608 Vulnerability in maven package org.jenkins-ci.main:jenkins-core