Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2025-68384

Опубликовано: 18 дек. 2025
Источник: redhat
CVSS3: 6.5
EPSS Низкий

Описание

Allocation of Resources Without Limits or Throttling (CWE-770) in Elasticsearch can allow a low-privileged authenticated user to cause Excessive Allocation (CAPEC-130) causing a persistent denial of service (OOM crash) via submission of oversized user settings data.

A flaw was found in Elasticsearch. A low-privileged authenticated user can cause an excessive memory allocation via submission of oversized user settings data, resulting in a denial of service.

Отчет

This issue can only be exploited by a low-privileged authenticated user, limiting the scope to legitimate users of Elasticsearch. Additionally, the only security impact of this flaw is a denial of service due to excessive memory allocation. Due to these reasons, this vulnerability has been rated with a moderate severity.

Меры по смягчению последствий

To mitigate this issue, make sure that only necessary and trusted users have authentication credentials to the Elasticsearch instance, limiting the ability of malicious users to potentially exploit this vulnerability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Logging Subsystem for Red Hat OpenShiftelasticsearch-coreFix deferred
Logging Subsystem for Red Hat OpenShiftopenshift-logging/elasticsearch6-rhel9Fix deferred
Logging Subsystem for Red Hat OpenShiftopenshift-logging/elasticsearch-operator-bundleFix deferred
Logging Subsystem for Red Hat OpenShiftopenshift-logging/elasticsearch-proxy-rhel9Fix deferred
Logging Subsystem for Red Hat OpenShiftopenshift-logging/elasticsearch-rhel9-operatorFix deferred
Logging Subsystem for Red Hat OpenShiftopenshift-logging/kibana6-rhel8Fix deferred
Logging Subsystem for Red Hat OpenShiftopenshift-logging/logging-curator5-rhel9Fix deferred
Logging Subsystem for Red Hat OpenShiftx-pack-securityFix deferred
Red Hat Fuse 7elasticsearch-coreFix deferred
Red Hat JBoss Enterprise Application Platform 7elasticsearch-coreFix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-770
https://bugzilla.redhat.com/show_bug.cgi?id=2423742elasticsearch: Elasticsearch Allocation of Resources Without Limits or Throttling

EPSS

Процентиль: 18%
0.00057
Низкий

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.5
ubuntu
3 месяца назад

Allocation of Resources Without Limits or Throttling (CWE-770) in Elasticsearch can allow a low-privileged authenticated user to cause Excessive Allocation (CAPEC-130) causing a persistent denial of service (OOM crash) via submission of oversized user settings data.

CVSS3: 6.5
nvd
3 месяца назад

Allocation of Resources Without Limits or Throttling (CWE-770) in Elasticsearch can allow a low-privileged authenticated user to cause Excessive Allocation (CAPEC-130) causing a persistent denial of service (OOM crash) via submission of oversized user settings data.

msrc
3 месяца назад

Elasticsearch Allocation of Resources Without Limits or Throttling

CVSS3: 6.5
debian
3 месяца назад

Allocation of Resources Without Limits or Throttling (CWE-770) in Elas ...

CVSS3: 6.5
github
3 месяца назад

Elasticsearch has Excessive Allocation of Resources via Submission of Oversized User Settings Data

EPSS

Процентиль: 18%
0.00057
Низкий

6.5 Medium

CVSS3