VDB
Sign up
MEDIUM4.9

GHSA-4q22-422g-m4pj

Elasticsearch StackOverflow vulnerability

Quick fix

GHSA-4q22-422g-m4pj — org.elasticsearch:elasticsearch: upgrade to the fixed version with the command below.

# pom.xml: bump <version>8.14.0</version> for org.elasticsearch:elasticsearch

Details

A flaw was discovered in Elasticsearch, affecting document ingestion when an index template contains a dynamic field mapping of “passthrough” type. Under certain circumstances, ingesting documents in this index would cause a StackOverflow exception to be thrown and ultimately lead to a Denial of Service. Note that passthrough fields is an experimental feature.

Are you affected?

Enter the version of the package you're using.

Affected packages

Maven/org.elasticsearch:elasticsearch
Introduced in: 8.13.1Fixed in: 8.14.0
Fix# pom.xml: bump <version>8.14.0</version> for org.elasticsearch:elasticsearch

References