Deserialization of Untrusted Data in Elasticsearch for Apache Hadoop - CVE-2023-46674
Published: December 6, 2023
Vulnerability identifier: #VU83893
CSH Severity: Medium
CVSS v4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-46674
CWE-ID: CWE-502
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote user to execute arbitrary code on the target system.
The vulnerability exists due to insecure input validation when processing serialized data in hadoop or spark configuration properties. A remote user can update configuration properties and execute arbitrary code on the target system.
Affected software
Elasticsearch for Apache Hadoop
watsonx.data
Watson CP4D Data Stores
watsonx.data
Watson CP4D Data Stores
How to mitigate CVE-2023-46674
Install updates from vendor's website.
Elasticsearch for Apache Hadoop - addressed in versions 7.17.11, 8.9.0
watsonx.data - update to 2.0.2
Watson CP4D Data Stores - update to 5.0
watsonx.data - update to 2.0.2
Watson CP4D Data Stores - update to 5.0