VDB
Sign up
MEDIUM4.9

GHSA-gphj-4h6p-37xq

Elasticsearch privileged authenticated users can cause DoS through Excessive Resource Allocation

Quick fix

GHSA-gphj-4h6p-37xq — org.elasticsearch.plugin:x-pack-core: upgrade to the fixed version with the command below.

# pom.xml: bump <version>8.19.8</version> for org.elasticsearch.plugin:x-pack-core

Details

Allocation of Resources Without Limits or Throttling (CWE-770) in Elasticsearch can allow an authenticated user with snapshot restore privileges to cause Excessive Allocation (CAPEC-130) of memory and a denial of service (DoS) via crafted HTTP request.

Are you affected?

Enter the version of the package you're using.

Affected packages

Maven/org.elasticsearch.plugin:x-pack-core
Introduced in: 0Fixed in: 8.19.8
Fix# pom.xml: bump <version>8.19.8</version> for org.elasticsearch.plugin:x-pack-core
Maven/org.elasticsearch.plugin:x-pack-core
Introduced in: 9.0.0Fixed in: 9.1.8
Fix# pom.xml: bump <version>9.1.8</version> for org.elasticsearch.plugin:x-pack-core
Maven/org.elasticsearch.plugin:x-pack-core
Introduced in: 9.2.0Fixed in: 9.2.2
Fix# pom.xml: bump <version>9.2.2</version> for org.elasticsearch.plugin:x-pack-core

References