ElasticsearchGHSA-3393-hvrj-w7v3
Denial of Service in Elasticsearch
Medium5.7CVE-2021-22144 · Published Aug 9, 2021 · updated Feb 20, 2024
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| org.elasticsearch:elasticsearch Maven | < 6.8.17 | 6.8.17 |
| >= 7.0.0-alpha1, < 7.13.3 | 7.13.3 |
Details and references
In Elasticsearch versions before 7.13.3 and 6.8.17 an uncontrolled recursion vulnerability that could lead to a denial of service attack was identified in the Elasticsearch Grok parser. A user with the ability to submit arbitrary queries to Elasticsearch could create a malicious Grok query that will crash the Elasticsearch node.
- CVSS 3.1
- CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-674
- Also known as
- BIT-elasticsearch-2021-22144, CVE-2021-22144
More Elasticsearch advisories
All Elasticsearch| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Jul 22021 | API information disclosure flaw in Elasticsearch CVE-2021-22135Medium5.3fixed in 6.8.15, 7.11.2 | Medium5.3 | 6.8.15, 7.11.2 |
| Sep 202021 | Exposure of sensitive information in Elasticsearch CVE-2021-22147Medium6.5fixed in 7.14.0 | Medium6.5 | 7.14.0 |
| Mar 182021 | Insufficiently Protected Credentials in Elasticsearch CVE-2021-22132Medium4.8fixed in 7.10.2 | Medium4.8 | 7.10.2 |
| Mar 182021 | Privilege Escalation Flaw in Elasticsearch CVE-2020-7014Medium8.8fixed in 6.8.8, 7.6.2 | Medium8.8 | 6.8.8, 7.6.2 |
| Mar 182021 | Privilege Context Switching Error in Elasticsearch CVE-2020-7020Low3.1fixed in 6.8.13, 7.9.2 | Low3.1 | 6.8.13, 7.9.2 |
| Mar 182021 | Exposure of Sensitive Information to an Unauthorized Actor CVE-2021-22134Medium4.3fixed in 7.11.0 | Medium4.3 | 7.11.0 |