CVE-2023-46673

Source
https://cve.org/CVERecord?id=CVE-2023-46673
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-46673.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2023-46673
Aliases
Downstream
Published
2023-11-22T10:15:08.417Z
Modified
2026-03-14T12:16:15.544740Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
[none]
Details

It was identified that malformed scripts used in the script processor of an Ingest Pipeline could cause an Elasticsearch node to crash when calling the Simulate Pipeline API.

References

Affected packages

Git / github.com/elastic/elasticsearch

Affected ranges

Type
GIT
Repo
https://github.com/elastic/elasticsearch
Events
Database specific
{
    "versions": [
        {
            "introduced": "7.0.0"
        },
        {
            "fixed": "7.17.14"
        },
        {
            "introduced": "8.0.0"
        },
        {
            "fixed": "8.10.3"
        }
    ]
}

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-46673.json"
vanir_signatures
[
    {
        "deprecated": false,
        "signature_type": "Line",
        "signature_version": "v1",
        "digest": {
            "line_hashes": [
                "143555046380899976224642292835931628359",
                "95679163715031140699700865949707396022",
                "3858837225766748725661372356006647359",
                "190231679334487928784662528136086062290"
            ],
            "threshold": 0.9
        },
        "source": "https://github.com/elastic/elasticsearch/commit/c63272efed16b5a1c25f3ce500715b7fddf9a9fb",
        "id": "CVE-2023-46673-1316c5ba",
        "target": {
            "file": "test/test-clusters/src/main/java/org/elasticsearch/test/cluster/local/DefaultLocalClusterSpecBuilder.java"
        }
    },
    {
        "deprecated": false,
        "signature_type": "Line",
        "signature_version": "v1",
        "digest": {
            "line_hashes": [
                "329406936970782249139919767545216631531",
                "203820848483684539800570148075078700006",
                "210926884174254579773410981724726245993",
                "109549252725012340165422930880956364048",
                "86702312112542064643402696924147009991",
                "146717229414333023258558344616211119473",
                "211757186117026870230612772988484608816"
            ],
            "threshold": 0.9
        },
        "source": "https://github.com/elastic/elasticsearch/commit/c63272efed16b5a1c25f3ce500715b7fddf9a9fb",
        "id": "CVE-2023-46673-16cc81d3",
        "target": {
            "file": "x-pack/plugin/src/yamlRestTest/java/org/elasticsearch/xpack/test/rest/XPackRestIT.java"
        }
    },
    {
        "deprecated": false,
        "signature_type": "Function",
        "signature_version": "v1",
        "digest": {
            "function_hash": "325784271606612404164400123082142816971",
            "length": 3690.0
        },
        "source": "https://github.com/elastic/elasticsearch/commit/774e3bfa4d52e2834e4d9d8d669d77e4e5c1017f",
        "id": "CVE-2023-46673-84cc319c",
        "target": {
            "file": "build-tools-internal/src/main/java/org/elasticsearch/gradle/internal/testfixtures/TestFixturesPlugin.java",
            "function": "apply"
        }
    },
    {
        "deprecated": false,
        "signature_type": "Line",
        "signature_version": "v1",
        "digest": {
            "line_hashes": [
                "305397982476570854131184393422281802034",
                "100542449908851490517382426102539479787",
                "214587582970408227284909587357119016735",
                "285970827320131388487951052299321287047",
                "41453645292239769522791082638784997580",
                "328227527869521250077606291737843585093",
                "10140825892038828328726688010826312150",
                "264992127695632620499514457325143505965"
            ],
            "threshold": 0.9
        },
        "source": "https://github.com/elastic/elasticsearch/commit/774e3bfa4d52e2834e4d9d8d669d77e4e5c1017f",
        "id": "CVE-2023-46673-afd122e0",
        "target": {
            "file": "build-tools-internal/src/main/java/org/elasticsearch/gradle/internal/testfixtures/TestFixturesPlugin.java"
        }
    },
    {
        "deprecated": false,
        "signature_type": "Function",
        "signature_version": "v1",
        "digest": {
            "function_hash": "126727165705535679521501470156764842749",
            "length": 216.0
        },
        "source": "https://github.com/elastic/elasticsearch/commit/c63272efed16b5a1c25f3ce500715b7fddf9a9fb",
        "id": "CVE-2023-46673-c8641b23",
        "target": {
            "file": "test/test-clusters/src/main/java/org/elasticsearch/test/cluster/local/DefaultLocalClusterSpecBuilder.java",
            "function": "DefaultLocalClusterSpecBuilder"
        }
    },
    {
        "deprecated": false,
        "signature_type": "Line",
        "signature_version": "v1",
        "digest": {
            "line_hashes": [
                "87430569100128500062132965632081964994",
                "220230106846710630873578755849001445563",
                "143242041297247146171923080539894105454",
                "300730341766753273516600498462172618276"
            ],
            "threshold": 0.9
        },
        "source": "https://github.com/elastic/elasticsearch/commit/c63272efed16b5a1c25f3ce500715b7fddf9a9fb",
        "id": "CVE-2023-46673-fcfa0b3a",
        "target": {
            "file": "test/test-clusters/src/main/java/org/elasticsearch/test/cluster/FeatureFlag.java"
        }
    }
]