{"id":"CVE-2023-46673","details":"It was identified that malformed scripts used in the script processor of an Ingest Pipeline could cause an Elasticsearch node to crash when calling the Simulate Pipeline API.\n","aliases":["BIT-elasticsearch-2023-46673","GHSA-285m-vhfq-xx4h"],"modified":"2026-03-14T12:16:15.544740Z","published":"2023-11-22T10:15:08.417Z","references":[{"type":"ADVISORY","url":"https://discuss.elastic.co/t/elasticsearch-7-17-14-8-10-3-security-update-esa-2023-24/347708"},{"type":"ADVISORY","url":"https://www.elastic.co/community/security"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/elastic/elasticsearch","events":[{"introduced":"b7e28a7232616c7a21bc879a535d801b8553ba77"},{"fixed":"774e3bfa4d52e2834e4d9d8d669d77e4e5c1017f"},{"introduced":"1b6a7ece17463df5ff54a3e1302d825889aa1161"},{"fixed":"c63272efed16b5a1c25f3ce500715b7fddf9a9fb"}],"database_specific":{"versions":[{"introduced":"7.0.0"},{"fixed":"7.17.14"},{"introduced":"8.0.0"},{"fixed":"8.10.3"}]}}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-46673.json","vanir_signatures":[{"signature_version":"v1","deprecated":false,"id":"CVE-2023-46673-1316c5ba","digest":{"line_hashes":["143555046380899976224642292835931628359","95679163715031140699700865949707396022","3858837225766748725661372356006647359","190231679334487928784662528136086062290"],"threshold":0.9},"target":{"file":"test/test-clusters/src/main/java/org/elasticsearch/test/cluster/local/DefaultLocalClusterSpecBuilder.java"},"source":"https://github.com/elastic/elasticsearch/commit/c63272efed16b5a1c25f3ce500715b7fddf9a9fb","signature_type":"Line"},{"signature_version":"v1","deprecated":false,"id":"CVE-2023-46673-16cc81d3","digest":{"line_hashes":["329406936970782249139919767545216631531","203820848483684539800570148075078700006","210926884174254579773410981724726245993","109549252725012340165422930880956364048","86702312112542064643402696924147009991","146717229414333023258558344616211119473","211757186117026870230612772988484608816"],"threshold":0.9},"target":{"file":"x-pack/plugin/src/yamlRestTest/java/org/elasticsearch/xpack/test/rest/XPackRestIT.java"},"source":"https://github.com/elastic/elasticsearch/commit/c63272efed16b5a1c25f3ce500715b7fddf9a9fb","signature_type":"Line"},{"signature_version":"v1","deprecated":false,"id":"CVE-2023-46673-84cc319c","digest":{"length":3690,"function_hash":"325784271606612404164400123082142816971"},"target":{"function":"apply","file":"build-tools-internal/src/main/java/org/elasticsearch/gradle/internal/testfixtures/TestFixturesPlugin.java"},"source":"https://github.com/elastic/elasticsearch/commit/774e3bfa4d52e2834e4d9d8d669d77e4e5c1017f","signature_type":"Function"},{"signature_version":"v1","deprecated":false,"id":"CVE-2023-46673-afd122e0","digest":{"line_hashes":["305397982476570854131184393422281802034","100542449908851490517382426102539479787","214587582970408227284909587357119016735","285970827320131388487951052299321287047","41453645292239769522791082638784997580","328227527869521250077606291737843585093","10140825892038828328726688010826312150","264992127695632620499514457325143505965"],"threshold":0.9},"target":{"file":"build-tools-internal/src/main/java/org/elasticsearch/gradle/internal/testfixtures/TestFixturesPlugin.java"},"source":"https://github.com/elastic/elasticsearch/commit/774e3bfa4d52e2834e4d9d8d669d77e4e5c1017f","signature_type":"Line"},{"signature_version":"v1","deprecated":false,"id":"CVE-2023-46673-c8641b23","digest":{"length":216,"function_hash":"126727165705535679521501470156764842749"},"target":{"function":"DefaultLocalClusterSpecBuilder","file":"test/test-clusters/src/main/java/org/elasticsearch/test/cluster/local/DefaultLocalClusterSpecBuilder.java"},"source":"https://github.com/elastic/elasticsearch/commit/c63272efed16b5a1c25f3ce500715b7fddf9a9fb","signature_type":"Function"},{"signature_version":"v1","deprecated":false,"id":"CVE-2023-46673-fcfa0b3a","digest":{"line_hashes":["87430569100128500062132965632081964994","220230106846710630873578755849001445563","143242041297247146171923080539894105454","300730341766753273516600498462172618276"],"threshold":0.9},"target":{"file":"test/test-clusters/src/main/java/org/elasticsearch/test/cluster/FeatureFlag.java"},"source":"https://github.com/elastic/elasticsearch/commit/c63272efed16b5a1c25f3ce500715b7fddf9a9fb","signature_type":"Line"}]}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}]}