MEDIUM4.9
GHSA-gphj-4h6p-37xq
Elasticsearch privileged authenticated users can cause DoS through Excessive Resource Allocation
Quick fix
GHSA-gphj-4h6p-37xq — org.elasticsearch.plugin:x-pack-core: upgrade to the fixed version with the command below.
# pom.xml: bump <version>8.19.8</version> for org.elasticsearch.plugin:x-pack-coreDetails
Allocation of Resources Without Limits or Throttling (CWE-770) in Elasticsearch can allow an authenticated user with snapshot restore privileges to cause Excessive Allocation (CAPEC-130) of memory and a denial of service (DoS) via crafted HTTP request.
Are you affected?
Enter the version of the package you're using.
Affected packages
Maven/org.elasticsearch.plugin:x-pack-core
Introduced in:
0Fixed in: 8.19.8Fix
# pom.xml: bump <version>8.19.8</version> for org.elasticsearch.plugin:x-pack-coreMaven/org.elasticsearch.plugin:x-pack-core
Introduced in:
9.0.0Fixed in: 9.1.8Fix
# pom.xml: bump <version>9.1.8</version> for org.elasticsearch.plugin:x-pack-coreMaven/org.elasticsearch.plugin:x-pack-core
Introduced in:
9.2.0Fixed in: 9.2.2Fix
# pom.xml: bump <version>9.2.2</version> for org.elasticsearch.plugin:x-pack-core