Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-3393-hvrj-w7v3

Опубликовано: 09 авг. 2021
Источник: github
Github: Прошло ревью
CVSS3: 5.7

Описание

Denial of Service in Elasticsearch

In Elasticsearch versions before 7.13.3 and 6.8.17 an uncontrolled recursion vulnerability that could lead to a denial of service attack was identified in the Elasticsearch Grok parser. A user with the ability to submit arbitrary queries to Elasticsearch could create a malicious Grok query that will crash the Elasticsearch node.

Пакеты

Наименование

org.elasticsearch:elasticsearch

maven
Затронутые версииВерсия исправления

< 6.8.17

6.8.17

Наименование

org.elasticsearch:elasticsearch

maven
Затронутые версииВерсия исправления

>= 7.0.0-alpha1, < 7.13.3

7.13.3

EPSS

Процентиль: 43%
0.00211
Низкий

5.7 Medium

CVSS3

Дефекты

CWE-674

Связанные уязвимости

CVSS3: 6.5
ubuntu
больше 4 лет назад

In Elasticsearch versions before 7.13.3 and 6.8.17 an uncontrolled recursion vulnerability that could lead to a denial of service attack was identified in the Elasticsearch Grok parser. A user with the ability to submit arbitrary queries to Elasticsearch could create a malicious Grok query that will crash the Elasticsearch node.

CVSS3: 6.5
redhat
больше 4 лет назад

In Elasticsearch versions before 7.13.3 and 6.8.17 an uncontrolled recursion vulnerability that could lead to a denial of service attack was identified in the Elasticsearch Grok parser. A user with the ability to submit arbitrary queries to Elasticsearch could create a malicious Grok query that will crash the Elasticsearch node.

CVSS3: 6.5
nvd
больше 4 лет назад

In Elasticsearch versions before 7.13.3 and 6.8.17 an uncontrolled recursion vulnerability that could lead to a denial of service attack was identified in the Elasticsearch Grok parser. A user with the ability to submit arbitrary queries to Elasticsearch could create a malicious Grok query that will crash the Elasticsearch node.

CVSS3: 6.5
msrc
около 4 лет назад

In Elasticsearch versions before 7.13.3 and 6.8.17 an uncontrolled recursion vulnerability that could lead to a denial of service attack was identified in the Elasticsearch Grok parser. A user with the ability to submit arbitrary queries to Elasticsearch could create a malicious Grok query that will crash the Elasticsearch node.

CVSS3: 6.5
debian
больше 4 лет назад

In Elasticsearch versions before 7.13.3 and 6.8.17 an uncontrolled rec ...

EPSS

Процентиль: 43%
0.00211
Низкий

5.7 Medium

CVSS3

Дефекты

CWE-674