Description
It was identified that malformed scripts used in the script processor of an Ingest Pipeline could cause an Elasticsearch node to crash when calling the Simulate Pipeline API.
Remediation
References
https://discuss.elastic.co/t/elasticsearch-7-17-14-8-10-3-security-update-esa-2023-24/347708
https://www.elastic.co/community/security
Related Vulnerabilities
CVE-2021-21349 Vulnerability in maven package com.thoughtworks.xstream:xstream
CVE-2015-6420 Vulnerability in maven package commons-collections:commons-collections
CVE-2010-3718 Vulnerability in maven package org.apache.tomcat.embed:tomcat-embed-core
CVE-2009-2902 Vulnerability in maven package tomcat:catalina
CVE-2012-5885 Vulnerability in maven package org.apache.tomcat:catalina