Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-4q22-422g-m4pj

Опубликовано: 13 июн. 2024
Источник: github
Github: Прошло ревью
CVSS3: 4.9

Описание

Elasticsearch StackOverflow vulnerability

A flaw was discovered in Elasticsearch, affecting document ingestion when an index template contains a dynamic field mapping of “passthrough” type. Under certain circumstances, ingesting documents in this index would cause a StackOverflow exception to be thrown and ultimately lead to a Denial of Service. Note that passthrough fields is an experimental feature.

Пакеты

Наименование

org.elasticsearch:elasticsearch

maven
Затронутые версииВерсия исправления

>= 8.13.1, < 8.14.0

8.14.0

EPSS

Процентиль: 47%
0.00618
Низкий

4.9 Medium

CVSS3

Дефекты

CWE-122
CWE-787

Связанные уязвимости

CVSS3: 4.9
ubuntu
около 2 лет назад

A flaw was discovered in Elasticsearch, affecting document ingestion when an index template contains a dynamic field mapping of “passthrough” type. Under certain circumstances, ingesting documents in this index would cause a StackOverflow exception to be thrown and ultimately lead to a Denial of Service. Note that passthrough fields is an experimental feature.

CVSS3: 4.9
redhat
около 2 лет назад

A flaw was discovered in Elasticsearch, affecting document ingestion when an index template contains a dynamic field mapping of “passthrough” type. Under certain circumstances, ingesting documents in this index would cause a StackOverflow exception to be thrown and ultimately lead to a Denial of Service. Note that passthrough fields is an experimental feature.

CVSS3: 4.9
nvd
около 2 лет назад

A flaw was discovered in Elasticsearch, affecting document ingestion when an index template contains a dynamic field mapping of “passthrough” type. Under certain circumstances, ingesting documents in this index would cause a StackOverflow exception to be thrown and ultimately lead to a Denial of Service. Note that passthrough fields is an experimental feature.

CVSS3: 4.9
debian
около 2 лет назад

A flaw was discovered in Elasticsearch, affecting document ingestion w ...

EPSS

Процентиль: 47%
0.00618
Низкий

4.9 Medium

CVSS3

Дефекты

CWE-122
CWE-787