Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2021-22144

Опубликовано: 07 июл. 2021
Источник: redhat
CVSS3: 6.5
EPSS Низкий

Описание

In Elasticsearch versions before 7.13.3 and 6.8.17 an uncontrolled recursion vulnerability that could lead to a denial of service attack was identified in the Elasticsearch Grok parser. A user with the ability to submit arbitrary queries to Elasticsearch could create a malicious Grok query that will crash the Elasticsearch node.

A flaw was found in Elasticsearch. An uncontrolled recursion vulnerability that could lead to a denial of service attack was identified in the Elasticsearch Grok parser. This flaw allows a user who can submit arbitrary queries to Elasticsearch to create a malicious Grok query that crashes the Elasticsearch node. The highest threat from this vulnerability is to system availability.

Отчет

OpenShift Container Platform (OCP) includes an affected version of Elasticsearch in logging-elasticsearch containers. However, Grok is not bundled by Red Hat in the shipped version of Elasticsearch and hence OCP is not affected by this vulnerability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Logging Subsystem for Red Hat OpenShiftopenshift-logging/elasticsearch6-rhel8Not affected
OpenShift Service Mesh 1servicemesh-grafanaOut of support scope
OpenShift Service Mesh 2.0servicemesh-grafanaNot affected
Red Hat Decision Manager 7elasticsearchWill not fix
Red Hat Fuse 7elasticsearchNot affected
Red Hat Integration Camel K 1elasticsearchNot affected
Red Hat JBoss Data Grid 6elasticsearchOut of support scope
Red Hat JBoss Fuse 6elasticsearchOut of support scope
Red Hat JBoss Fuse Service Works 6elasticsearchOut of support scope
Red Hat OpenShift Container Platform 3.11openshift3/ose-logging-elasticsearch5Not affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-674
https://bugzilla.redhat.com/show_bug.cgi?id=1987299elasticsearch: uncontrolled recursion in Grok parser

EPSS

Процентиль: 43%
0.00211
Низкий

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.5
ubuntu
больше 4 лет назад

In Elasticsearch versions before 7.13.3 and 6.8.17 an uncontrolled recursion vulnerability that could lead to a denial of service attack was identified in the Elasticsearch Grok parser. A user with the ability to submit arbitrary queries to Elasticsearch could create a malicious Grok query that will crash the Elasticsearch node.

CVSS3: 6.5
nvd
больше 4 лет назад

In Elasticsearch versions before 7.13.3 and 6.8.17 an uncontrolled recursion vulnerability that could lead to a denial of service attack was identified in the Elasticsearch Grok parser. A user with the ability to submit arbitrary queries to Elasticsearch could create a malicious Grok query that will crash the Elasticsearch node.

CVSS3: 6.5
msrc
около 4 лет назад

In Elasticsearch versions before 7.13.3 and 6.8.17 an uncontrolled recursion vulnerability that could lead to a denial of service attack was identified in the Elasticsearch Grok parser. A user with the ability to submit arbitrary queries to Elasticsearch could create a malicious Grok query that will crash the Elasticsearch node.

CVSS3: 6.5
debian
больше 4 лет назад

In Elasticsearch versions before 7.13.3 and 6.8.17 an uncontrolled rec ...

CVSS3: 5.7
github
больше 4 лет назад

Denial of Service in Elasticsearch

EPSS

Процентиль: 43%
0.00211
Низкий

6.5 Medium

CVSS3