An uncaught exception in Elasticsearch >= 8.4.0 and < 8.11.1 occurs when an encrypted PDF is passed to an attachment processor through the REST API. The Elasticsearch ingest node that attempts to parse the PDF file will crash. This does not happen with password-protected PDF files or with unencrypted PDF files.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: elastic

Published: 2024-03-29T11:12:49.067Z

Updated: 2024-08-12T13:14:56.771Z

Reserved: 2024-01-16T21:31:26.030Z

Link: CVE-2024-23449

cve-icon Vulnrichment

Updated: 2024-08-01T23:06:24.587Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-03-29T12:15:08.177

Modified: 2024-03-29T12:45:02.937

Link: CVE-2024-23449

cve-icon Redhat

Severity : Moderate

Publid Date: 2024-03-29T00:00:00Z

Links: CVE-2024-23449 - Bugzilla