Input validation error in Elasticsearch - CVE-2023-46673

 

Input validation error in Elasticsearch - CVE-2023-46673

Published: November 22, 2023


Vulnerability identifier: #VU83419
CSH Severity: Medium
CVSS v4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-46673
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to perform a denial of service (DoS) attack.

The vulnerability exists due to insufficient validation of user-supplied input within the Simulate Pipeline API. A remote user can pass malformed scripts to the script processor of an Ingest Pipeline and perform a denial of service (DoS) attack.


Affected software

Elasticsearch
Business Automation Insights
watsonx.data
IBM Watson Assistant for IBM Cloud Pak for Data
IBM Watson Discovery for IBM Cloud Pak for Data
IBM Cloud Pak for Business Automation

How to mitigate CVE-2023-46673

Install updates from vendor's website.

Elasticsearch - addressed in versions 7.17.14, 8.10.3
Business Automation Insights - update to 23.0.2.0.1
watsonx.data - update to 2.0.2
IBM Watson Assistant for IBM Cloud Pak for Data - update to 4.8.2
IBM Watson Discovery for IBM Cloud Pak for Data - addressed in versions 4.8.6, 5.0.0
IBM Cloud Pak for Business Automation - addressed in versions 21.0.3.29, 23.0.2.1

External References

Related Security Bulletins