vulnerability
Elastic Elasticsearch: CVE-2024-23449: Uncaught Exception
| Severity | CVSS | Published | Added | Modified |
|---|---|---|---|---|
| 4 | (AV:N/AC:L/Au:S/C:N/I:N/A:P) | Mar 29, 2024 | May 13, 2025 | Jul 2, 2025 |
Severity
4
CVSS
(AV:N/AC:L/Au:S/C:N/I:N/A:P)
Published
Mar 29, 2024
Added
May 13, 2025
Modified
Jul 2, 2025
Description
An uncaught exception in Elasticsearch greater than or equal to 8.4.0 and less than 8.11.1 occurs when an encrypted PDF is passed to an attachment processor through the REST API. The Elasticsearch ingest node that attempts to parse the PDF file will crash. This does not happen with password-protected PDF files or with unencrypted PDF files.
Solution
elastic-elasticsearch-upgrade-latest
NEW
Explore Exposure Command
Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.