Description
It was identified that malformed scripts used in the script processor of an Ingest Pipeline could cause an Elasticsearch node to crash when calling the Simulate Pipeline API.
Remediation
References
https://discuss.elastic.co/t/elasticsearch-7-17-14-8-10-3-security-update-esa-2023-24/347708
https://www.elastic.co/community/security
Related Vulnerabilities
CVE-2017-15703 Vulnerability in maven package org.apache.nifi:nifi-security-utils
CVE-2022-43415 Vulnerability in maven package org.jenkins-ci.plugins:repo
CVE-2022-43432 Vulnerability in maven package org.jenkins-ci.plugins:xframium
CVE-2018-1274 Vulnerability in maven package org.springframework.data:spring-data-commons