Description
It was identified that malformed scripts used in the script processor of an Ingest Pipeline could cause an Elasticsearch node to crash when calling the Simulate Pipeline API.
Remediation
References
https://discuss.elastic.co/t/elasticsearch-7-17-14-8-10-3-security-update-esa-2023-24/347708
https://www.elastic.co/community/security
Related Vulnerabilities
CVE-2021-21366 Vulnerability in npm package xmldom
CVE-2020-2199 Vulnerability in maven package org.jenkins-ci.plugins:subversion
CVE-2022-29405 Vulnerability in maven package org.apache.archiva:archiva
CVE-2017-12174 Vulnerability in maven package org.apache.activemq:artemis-core-client
CVE-2014-0050 Vulnerability in maven package org.apache.jackrabbit:oak-run