CVE-2023-31419

Severity CVSS v4.0:
Pending analysis
Type:
CWE-121 Stack-based Buffer Overflow
Publication date:
26/10/2023
Last modified:
13/02/2025

Description

A flaw was discovered in Elasticsearch, affecting the _search API that allowed a specially crafted query string to cause a Stack Overflow and ultimately a Denial of Service.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:elastic:elasticsearch:*:*:*:*:*:*:*:* 7.0.0 (including) 7.17.12 (including)
cpe:2.3:a:elastic:elasticsearch:*:*:*:*:*:*:*:* 8.0.0 (including) 8.9.0 (including)