Stack-based buffer overflow in Elasticsearch - CVE-2023-31419

 

Stack-based buffer overflow in Elasticsearch - CVE-2023-31419

Published: September 19, 2023 / Updated: October 25, 2024


Vulnerability identifier: #VU80874
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-31419
CWE-ID: CWE-121
Exploitation vector: Remote access
Exploit availability: Public exploit is available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to a boundary error within the _search API. A remote attacker can pass specially crafted data to the application, trigger a stack buffer overflow and perform a denial of service (DoS) attack.


Affected software

Elasticsearch
IBM Cloud Pak for Business Automation
IBM Watson Assistant for IBM Cloud Pak for Data
IBM Watson Discovery for IBM Cloud Pak for Data
DataPower Operations Dashboard
watsonx.data

How to mitigate CVE-2023-31419

Install updates from vendor's website.

Elasticsearch - addressed in versions 7.17.13, 8.9.1
IBM Cloud Pak for Business Automation - addressed in versions 21.0.3.26, 23.0.1.4
DataPower Operations Dashboard - update to 1.0.20.1
watsonx.data - update to 2.0.2
IBM Watson Assistant for IBM Cloud Pak for Data - update to 4.8.2
IBM Watson Discovery for IBM Cloud Pak for Data - addressed in versions 4.8.6, 5.0.0

Links to Public Exploits and PoC-codes

External References

Related Security Bulletins