vulnerability

Elastic Elasticsearch: CVE-2024-23449: Uncaught Exception

Severity
4
CVSS
(AV:N/AC:L/Au:S/C:N/I:N/A:P)
Published
Mar 29, 2024
Added
May 13, 2025
Modified
Jul 2, 2025

Description

An uncaught exception in Elasticsearch greater than or equal to 8.4.0 and less than 8.11.1 occurs when an encrypted PDF is passed to an attachment processor through the REST API. The Elasticsearch ingest node that attempts to parse the PDF file will crash. This does not happen with password-protected PDF files or with unencrypted PDF files.

Solution

elastic-elasticsearch-upgrade-latest
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.