Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-gphj-4h6p-37xq

Опубликовано: 19 дек. 2025
Источник: github
Github: Прошло ревью
CVSS3: 4.9

Описание

Elasticsearch privileged authenticated users can cause DoS through Excessive Resource Allocation

Allocation of Resources Without Limits or Throttling (CWE-770) in Elasticsearch can allow an authenticated user with snapshot restore privileges to cause Excessive Allocation (CAPEC-130) of memory and a denial of service (DoS) via crafted HTTP request.

Пакеты

Наименование

org.elasticsearch.plugin:x-pack-core

maven
Затронутые версииВерсия исправления

< 8.19.8

8.19.8

Наименование

org.elasticsearch.plugin:x-pack-core

maven
Затронутые версииВерсия исправления

>= 9.0.0, < 9.1.8

9.1.8

Наименование

org.elasticsearch.plugin:x-pack-core

maven
Затронутые версииВерсия исправления

>= 9.2.0, < 9.2.2

9.2.2

EPSS

Процентиль: 34%
0.00137
Низкий

4.9 Medium

CVSS3

Дефекты

CWE-770

Связанные уязвимости

CVSS3: 4.9
ubuntu
около 2 месяцев назад

Allocation of Resources Without Limits or Throttling (CWE-770) in Elasticsearch can allow an authenticated user with snapshot restore privileges to cause Excessive Allocation (CAPEC-130) of memory and a denial of service (DoS) via crafted HTTP request.

CVSS3: 4.9
nvd
около 2 месяцев назад

Allocation of Resources Without Limits or Throttling (CWE-770) in Elasticsearch can allow an authenticated user with snapshot restore privileges to cause Excessive Allocation (CAPEC-130) of memory and a denial of service (DoS) via crafted HTTP request.

msrc
около 2 месяцев назад

Elasticsearch Allocation of Resources Without Limits or Throttling

CVSS3: 4.9
debian
около 2 месяцев назад

Allocation of Resources Without Limits or Throttling (CWE-770) in Elas ...

EPSS

Процентиль: 34%
0.00137
Низкий

4.9 Medium

CVSS3

Дефекты

CWE-770