An issue has been identified with how Elasticsearch handled incoming requests on the HTTP layer. An unauthenticated user could force an Elasticsearch node to exit with an OutOfMemory error by sending a moderate number of malformed HTTP requests. The issue was identified by Elastic Engineering and we have no indication that the issue is known or that it is being exploited in the wild.
oryginał ENCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HElastic Cloud Enterprise
APPElastic3.6.0≤ 2.13.3Elastic Elasticsearch
APPElastic≤ 7.17.128.0.0 – 8.8.2
Powiązane podatności
Elasticsearch: ucieczka z sandboksa Groovy i zdalne wykonanie poleceń
Elastic Cloud Enterprise — Server-Side Template Injection (SSTI) w silniku Jinjava
RCE w Elasticsearch przez protokół transportowy (przed wersją 1.6.1)
The default configuration in Elasticsearch before 1.2 enables dynamic scripting, which allows remote attackers...
Deserialization of Untrusted Data (CWE-502) in the Elasticsearch machine learning component can lead to remote...