Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2025-68390

Опубликовано: 18 дек. 2025
Источник: redhat
CVSS3: 4.9

Описание

Allocation of Resources Without Limits or Throttling (CWE-770) in Elasticsearch can allow an authenticated user with snapshot restore privileges to cause Excessive Allocation (CAPEC-130) of memory and a denial of service (DoS) via crafted HTTP request.

A flaw was found in Elasticsearch. An authenticated user, with snapshot restore privileges, can cause an excessive memory allocation via a crafted HTTP request, resulting in a denial of service.

Отчет

This issue can only be exploited by an authenticated user with snapshot restore privileges, limiting the scope to legitimate users of Elasticsearch. Additionally, the only security impact of this flaw is a denial of service due to excessive memory allocation. Due to these reasons, this vulnerability has been rated with a moderate severity.

Меры по смягчению последствий

To mitigate this issue, make sure that only necessary and trusted users have authentication credentials to the Elasticsearch instance with snapshot restore privileges, limiting the ability of malicious users to potentially exploit this vulnerability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Logging Subsystem for Red Hat OpenShiftelasticsearch-coreFix deferred
Logging Subsystem for Red Hat OpenShiftopenshift-logging/elasticsearch6-rhel9Fix deferred
Logging Subsystem for Red Hat OpenShiftopenshift-logging/elasticsearch-operator-bundleFix deferred
Logging Subsystem for Red Hat OpenShiftopenshift-logging/elasticsearch-proxy-rhel9Fix deferred
Logging Subsystem for Red Hat OpenShiftopenshift-logging/elasticsearch-rhel9-operatorFix deferred
Logging Subsystem for Red Hat OpenShiftopenshift-logging/kibana6-rhel8Fix deferred
Logging Subsystem for Red Hat OpenShiftopenshift-logging/logging-curator5-rhel9Fix deferred
Logging Subsystem for Red Hat OpenShiftx-pack-coreFix deferred
Red Hat Fuse 7elasticsearch-coreFix deferred
Red Hat JBoss Enterprise Application Platform 7elasticsearch-coreFix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-770
https://bugzilla.redhat.com/show_bug.cgi?id=2423744elasticsearch: Elasticsearch Allocation of Resources Without Limits or Throttling

4.9 Medium

CVSS3

Связанные уязвимости

CVSS3: 4.9
ubuntu
3 месяца назад

Allocation of Resources Without Limits or Throttling (CWE-770) in Elasticsearch can allow an authenticated user with snapshot restore privileges to cause Excessive Allocation (CAPEC-130) of memory and a denial of service (DoS) via crafted HTTP request.

CVSS3: 4.9
nvd
3 месяца назад

Allocation of Resources Without Limits or Throttling (CWE-770) in Elasticsearch can allow an authenticated user with snapshot restore privileges to cause Excessive Allocation (CAPEC-130) of memory and a denial of service (DoS) via crafted HTTP request.

msrc
3 месяца назад

Elasticsearch Allocation of Resources Without Limits or Throttling

CVSS3: 4.9
debian
3 месяца назад

Allocation of Resources Without Limits or Throttling (CWE-770) in Elas ...

CVSS3: 4.9
github
3 месяца назад

Elasticsearch privileged authenticated users can cause DoS through Excessive Resource Allocation

4.9 Medium

CVSS3