Meet Corgea at Black Hat, BSides Las Vegas & DEF CON
HIGH 7.5 Maven

Improper Check for Unusual or Exceptional Conditions in Elasticsearch

GHSA-wh6w-69xc-5rq5 · BIT-elasticsearch-2022-23712 · CVE-2022-23712

Published · Modified

Description

A Denial of Service flaw was discovered in Elasticsearch 8.0.0 through 8.2.0. Using this vulnerability, an unauthenticated attacker could forcibly shut down an Elasticsearch node with a specifically formatted network request. Version 8.2.1 contains a patch.

Ready to move

Start Securing

Free, no credit card | First findings in minutes