Denial of Service Vulnerability in Elasticsearch by Elastic
CVE-2022-23712

7.5HIGH

Key Information:

Vendor
Elastic
Vendor
CVE Published:
6 June 2022

Summary

A Denial of Service vulnerability exists in Elasticsearch, allowing unauthenticated attackers to disable an Elasticsearch node by sending a specifically crafted network request. This flaw could disrupt service availability, affecting applications relying on Elasticsearch for data storage and retrieval. Organizations using Elasticsearch must implement security patches to mitigate this vulnerability and maintain system uptime.

Affected Version(s)

elasticsearch versions 8.0.0 through 8.2.0

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.