Description
It was identified that malformed scripts used in the script processor of an Ingest Pipeline could cause an Elasticsearch node to crash when calling the Simulate Pipeline API.
Remediation
References
https://discuss.elastic.co/t/elasticsearch-7-17-14-8-10-3-security-update-esa-2023-24/347708
https://www.elastic.co/community/security
Related Vulnerabilities
CVE-2023-45827 Vulnerability in npm package @clickbar/dot-diver
CVE-2023-49374 Vulnerability in maven package com.jfinal:jfinal
CVE-2014-0363 Vulnerability in maven package org.igniterealtime.smack:smack-core
CVE-2023-46604 Vulnerability in maven package org.apache.activemq:activemq-client
CVE-2023-45137 Vulnerability in maven package org.xwiki.platform:xwiki-platform-web-templates