Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-qf7c-7r9h-mm92

Опубликовано: 19 дек. 2025
Источник: github
Github: Прошло ревью
CVSS3: 6.5

Описание

Elasticsearch has Excessive Allocation of Resources via Submission of Oversized User Settings Data

Allocation of Resources Without Limits or Throttling (CWE-770) in Elasticsearch can allow a low-privileged authenticated user to cause Excessive Allocation (CAPEC-130) causing a persistent denial of service (OOM crash) via submission of oversized user settings data.

Пакеты

Наименование

org.elasticsearch.plugin:x-pack-security

maven
Затронутые версииВерсия исправления

< 8.19.9

8.19.9

Наименование

org.elasticsearch.plugin:x-pack-security

maven
Затронутые версииВерсия исправления

>= 9.0.0, < 9.1.9

9.1.9

Наименование

org.elasticsearch.plugin:x-pack-security

maven
Затронутые версииВерсия исправления

>= 9.2.0, < 9.2.3

9.2.3

EPSS

Процентиль: 15%
0.00049
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-770

Связанные уязвимости

CVSS3: 6.5
ubuntu
около 2 месяцев назад

Allocation of Resources Without Limits or Throttling (CWE-770) in Elasticsearch can allow a low-privileged authenticated user to cause Excessive Allocation (CAPEC-130) causing a persistent denial of service (OOM crash) via submission of oversized user settings data.

CVSS3: 6.5
nvd
около 2 месяцев назад

Allocation of Resources Without Limits or Throttling (CWE-770) in Elasticsearch can allow a low-privileged authenticated user to cause Excessive Allocation (CAPEC-130) causing a persistent denial of service (OOM crash) via submission of oversized user settings data.

msrc
около 2 месяцев назад

Elasticsearch Allocation of Resources Without Limits or Throttling

CVSS3: 6.5
debian
около 2 месяцев назад

Allocation of Resources Without Limits or Throttling (CWE-770) in Elas ...

EPSS

Процентиль: 15%
0.00049
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-770