Bug 2272190 (CVE-2024-23449) - CVE-2024-23449 elasticsearch: uncaught exception leads to crash
Summary: CVE-2024-23449 elasticsearch: uncaught exception leads to crash
Keywords:
Status: NEW
Alias: CVE-2024-23449
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Product Security
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks: 2272203
TreeView+ depends on / blocked
 
Reported: 2024-03-29 13:59 UTC by Mauro Matteo Cascella
Modified: 2024-03-29 16:31 UTC (History)
16 users (show)

Fixed In Version: elasticsearch 8.11.1
Doc Type: ---
Doc Text:
A flaw was found in the Elasticsearch package. An uncaught exception occurs when an encrypted PDF is passed to an attachment processor through the REST API. The Elasticsearch ingest node that attempts to parse the PDF file will crash. This does not happen with password-protected PDF files or with unencrypted PDF files.
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description Mauro Matteo Cascella 2024-03-29 13:59:09 UTC
An uncaught exception in Elasticsearch >= 8.4.0 and < 8.11.1 occurs when an encrypted PDF is passed to an attachment processor through the REST API. The Elasticsearch ingest node that attempts to parse the PDF file will crash. This does not happen with password-protected PDF files or with unencrypted PDF files.

Upstream advisory:
https://discuss.elastic.co/t/elasticsearch-8-11-1-security-update-esa-2024-05/356458


Note You need to log in before you can comment on or make changes to this bug.