Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2022-23712

Опубликовано: 24 мая 2022
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

A Denial of Service flaw was discovered in Elasticsearch. Using this vulnerability, an unauthenticated attacker could forcibly shut down an Elasticsearch node with a specifically formatted network request.

A flaw was found in Elasticsearch. This flaw allows an unauthenticated attacker to forcibly shut down an Elasticsearch node with a specifically formatted network request, affecting system availability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat build of QuarkuselasticsearchNot affected
Red Hat Data Grid 8elasticsearchNot affected
Red Hat Decision Manager 7elasticsearchAffected
Red Hat Enterprise Linux 8grafanaNot affected
Red Hat Enterprise Linux 9grafanaNot affected
Red Hat Fuse 7elasticsearchNot affected
Red Hat Integration Camel Quarkus 1elasticsearchNot affected
Red Hat Integration Data Virtualisation OperatorelasticsearchNot affected
Red Hat JBoss Data Grid 7elasticsearchNot affected
Red Hat JBoss Enterprise Application Platform 7elasticsearchNot affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-248
https://bugzilla.redhat.com/show_bug.cgi?id=2094515elasticsearch: DoS via a specifically formatted network request

EPSS

Процентиль: 87%
0.03234
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 3 лет назад

A Denial of Service flaw was discovered in Elasticsearch. Using this vulnerability, an unauthenticated attacker could forcibly shut down an Elasticsearch node with a specifically formatted network request.

CVSS3: 7.5
nvd
больше 3 лет назад

A Denial of Service flaw was discovered in Elasticsearch. Using this vulnerability, an unauthenticated attacker could forcibly shut down an Elasticsearch node with a specifically formatted network request.

CVSS3: 7.5
msrc
больше 3 лет назад

A Denial of Service flaw was discovered in Elasticsearch. Using this vulnerability an unauthenticated attacker could forcibly shut down an Elasticsearch node with a specifically formatted network request.

CVSS3: 7.5
debian
больше 3 лет назад

A Denial of Service flaw was discovered in Elasticsearch. Using this v ...

CVSS3: 7.5
github
больше 3 лет назад

Improper Check for Unusual or Exceptional Conditions in Elasticsearch

EPSS

Процентиль: 87%
0.03234
Низкий

7.5 High

CVSS3