Description
A flaw was discovered in Elasticsearch, affecting the _search API that allowed a specially crafted query string to cause a Stack Overflow and ultimately a Denial of Service.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-qwrx-45xf-jjf7 | Elasticsearch vulnerable to stack overflow in the search API |
References
History
Thu, 13 Feb 2025 17:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A flaw was discovered in Elasticsearch, affecting the _search API that allowed a specially crafted query string to cause a Stack Overflow and ultimately a Denial of Service. | A flaw was discovered in Elasticsearch, affecting the _search API that allowed a specially crafted query string to cause a Stack Overflow and ultimately a Denial of Service. |
Status: PUBLISHED
Assigner: elastic
Published:
Updated: 2025-02-13T16:50:07.612Z
Reserved: 2023-04-27T18:54:56.704Z
Link: CVE-2023-31419
No data.
Status : Modified
Published: 2023-10-26T18:15:08.647
Modified: 2025-02-13T17:16:27.630
Link: CVE-2023-31419
OpenCVE Enrichment
No data.
Github GHSA