Description
It was identified that malformed scripts used in the script processor of an Ingest Pipeline could cause an Elasticsearch node to crash when calling the Simulate Pipeline API.
Remediation
References
https://discuss.elastic.co/t/elasticsearch-7-17-14-8-10-3-security-update-esa-2023-24/347708
https://www.elastic.co/community/security
Related Vulnerabilities
CVE-2020-2155 Vulnerability in maven package org.jenkins-ci.plugins:openshift-deployer
CVE-2015-1807 Vulnerability in maven package org.jenkins-ci.main:jenkins-core
CVE-2015-3191 Vulnerability in maven package org.cloudfoundry.identity:cloudfoundry-identity-login
CVE-2017-17068 Vulnerability in npm package auth0-js
CVE-2023-29511 Vulnerability in maven package org.xwiki.platform:xwiki-platform-administration-ui