CVE-2023-46673: Elastic Elasticsearch
High severity, CVSS 7.5. EPSS: 0.8% chance of exploitation in the next 30 days.
It was identified that malformed scripts used in the script processor of an Ingest Pipeline could cause an Elasticsearch node to crash when calling the Simulate Pipeline API.
Affected products
- Elastic Elasticsearch: from 7.0.0, before 7.17.14 (fixed in 7.17.14); from 8.0.0, before 8.10.3 (fixed in 8.10.3)
Published 2023-11-22. Last modified 2026-06-17.