MEDIUM 5.7 Maven
Denial of Service in Elasticsearch
GHSA-3393-hvrj-w7v3 · BIT-elasticsearch-2021-22144 · CVE-2021-22144
Published · Modified
Description
In Elasticsearch versions before 7.13.3 and 6.8.17 an uncontrolled recursion vulnerability that could lead to a denial of service attack was identified in the Elasticsearch Grok parser. A user with the ability to submit arbitrary queries to Elasticsearch could create a malicious Grok query that will crash the Elasticsearch node.
Ready to move
Start Securing
Free, no credit card | First findings in minutes