Denial of Service Vulnerability in Elasticsearch by Elastic
CVE-2022-23712
7.5HIGH
Summary
A Denial of Service vulnerability exists in Elasticsearch, allowing unauthenticated attackers to disable an Elasticsearch node by sending a specifically crafted network request. This flaw could disrupt service availability, affecting applications relying on Elasticsearch for data storage and retrieval. Organizations using Elasticsearch must implement security patches to mitigate this vulnerability and maintain system uptime.
Affected Version(s)
elasticsearch versions 8.0.0 through 8.2.0
References
CVSS V3.1
Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved