Resource management error in Elasticsearch - CVE-2024-23450

 

Resource management error in Elasticsearch - CVE-2024-23450

Published: March 28, 2024


Vulnerability identifier: #VU87905
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-23450
CWE-ID: CWE-399
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to improper management of internal resources within the application when processing a document in a deeply nested pipeline on an ingest node. A remote attacker can pass specially crafted data to the application and perform a denial of service (DoS) attack.


Affected software

Elasticsearch
IBM Cloud Pak for Watson AIOps
Watson CP4D Data Stores
IBM Watson Assistant for IBM Cloud Pak for Data
IBM Watson Discovery for IBM Cloud Pak for Data
IBM Spectrum Symphony
IBM Observability with Instana
watsonx.data
IBM Security SOAR

How to mitigate CVE-2024-23450

Install updates from vendor's website.

Elasticsearch - addressed in versions 7.17.19, 8.13.0
IBM Cloud Pak for Watson AIOps - update to 4.10.0
IBM Watson Assistant for IBM Cloud Pak for Data - update to 5.0.1
IBM Watson Discovery for IBM Cloud Pak for Data - update to 5.3.1
IBM Spectrum Symphony - update to 7.3.2 FP3
watsonx.data - update to 2.0.2
Watson CP4D Data Stores - update to 5.0.3
IBM Security SOAR - update to 51.0.2.1
IBM Observability with Instana - update to 274

External References

Related Security Bulletins