Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-w2gr-585j-r428

Опубликовано: 13 янв. 2026
Источник: github
Github: Прошло ревью
CVSS3: 6.5

Описание

Metricbeat affected by multiple denial of service vulnerabilities

Improper Validation of Array Index (CWE-129) exists in Metricbeat can allow an attacker to cause a Denial of Service through Input Data Manipulation (CAPEC-153) via specially crafted, malformed payloads sent to the Graphite server metricset or Zookeeper server metricset. Additionally, Improper Input Validation (CWE-20) exists in the Prometheus helper module that can allow an attacker to cause a Denial of Service through Input Data Manipulation (CAPEC-153) via specially crafted, malformed metric data.

Пакеты

Наименование

github.com/elastic/beats/v7

go
Затронутые версииВерсия исправления

< 7.0.0-alpha2.0.20251217054608-6e42552a23ce

7.0.0-alpha2.0.20251217054608-6e42552a23ce

Наименование

github.com/elastic/beats/v7

go
Затронутые версииВерсия исправления

>= 8.0.0, < 8.19.10

8.19.10

Наименование

github.com/elastic/beats/v7

go
Затронутые версииВерсия исправления

>= 9.0.0, < 9.1.10

9.1.10

Наименование

github.com/elastic/beats/v7

go
Затронутые версииВерсия исправления

>= 9.2.0, < 9.2.4

9.2.4

EPSS

Процентиль: 14%
0.00047
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-129

Связанные уязвимости

CVSS3: 6.5
nvd
25 дней назад

Improper Validation of Array Index (CWE-129) exists in Metricbeat can allow an attacker to cause a Denial of Service through Input Data Manipulation (CAPEC-153) via specially crafted, malformed payloads sent to the Graphite server metricset or Zookeeper server metricset. Additionally, Improper Input Validation (CWE-20) exists in the Prometheus helper module that can allow an attacker to cause a Denial of Service through Input Data Manipulation (CAPEC-153) via specially crafted, malformed metric data.

EPSS

Процентиль: 14%
0.00047
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-129