CVE-2023-31419: Elasticsearch StackOverflow vulnerability
A flaw was discovered in Elasticsearch affecting the search API that allowed a specially crafted query string to cause a stack overflow and ultimately a denial of service.
Other sources
A flaw was discovered in Elasticsearch, affecting the search API that allowed a specially crafted query string to cause a Stack Overflow and ultimately a Denial of Service.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-31419?
CVE-2023-31419 is a vulnerability discovered in Elasticsearch that allows a specially crafted query string to cause a Stack Overflow and ultimately a Denial of Service.
What is the severity of CVE-2023-31419?
CVE-2023-31419 has a severity rating of medium with a score of 6.5.
Which versions of Elasticsearch are affected by CVE-2023-31419?
Elasticsearch versions from 8.0.0 to 8.9.1 and from 7.0.0 to 7.17.13 are affected by CVE-2023-31419.
How can I fix CVE-2023-31419?
To fix CVE-2023-31419, update your Elasticsearch installation to version 8.9.1 or 7.17.13, depending on the Elasticsearch version you are using.
Where can I find more information about CVE-2023-31419?
You can find more information about CVE-2023-31419 on the Elastic community security page, the National Vulnerability Database (NVD) website, and the provided reference links.