VDB
WID-SEC-W-2023-1602
WID-SEC-W-2023-1602
PUBLISHED
CVSS 9.300000190734863 CRITICAL
Elasticsearch ist eine Open Source, verteilte Echtzeit-Suche und Analyse-Engine.
Risk Scores
CVSS 4.0
9.300000190734863
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Hitachi Ops Center < Viewpoint 10.9.3-00 | ||
| Hitachi Ops Center < Analyzer 10.9.3-00 | ||
| Open Source Elasticsearch < 8.8.2 | ||
| Open Source Elasticsearch < 7.17.11 |
Exploit Intelligence
- https://wid.cert-bund.de/.well-known/csaf/white/2023/wid-sec-w-2023-1602.json (circl)
- https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2023-1602 (circl)
- https://www.hitachi.com/products/it/software/security/info/vuls/hitachi-sec-2023-144/index.html (circl)
- https://discuss.elastic.co/t/elastic-cloud-enterprise-ece-2-13-3-3-3-0-security-update/338650 (circl)
- https://discuss.elastic.co/t/subject-elasticsearch-8-8-2-7-17-11-security-update/337205 (circl)
- druid-612f0710.json (github-poc)
Timeline
- Jun 29, 2023 CVE Published
- Oct 3, 2023 CVE Updated
References
- https://wid.cert-bund.de/.well-known/csaf/white/2023/wid-sec-w-2023-1602.json advisory
- https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2023-1602 advisory
- https://www.hitachi.com/products/it/software/security/info/vuls/hitachi-sec-2023-144/index.html url
- https://discuss.elastic.co/t/elastic-cloud-enterprise-ece-2-13-3-3-3-0-security-update/338650 url
- https://discuss.elastic.co/t/subject-elasticsearch-8-8-2-7-17-11-security-update/337205 url