VDB
Sign up
MEDIUM6.5

GHSA-qf7c-7r9h-mm92

Elasticsearch has Excessive Allocation of Resources via Submission of Oversized User Settings Data

Quick fix

GHSA-qf7c-7r9h-mm92 — org.elasticsearch.plugin:x-pack-security: upgrade to the fixed version with the command below.

# pom.xml: bump <version>8.19.9</version> for org.elasticsearch.plugin:x-pack-security

Details

Allocation of Resources Without Limits or Throttling (CWE-770) in Elasticsearch can allow a low-privileged authenticated user to cause Excessive Allocation (CAPEC-130) causing a persistent denial of service (OOM crash) via submission of oversized user settings data.

Are you affected?

Enter the version of the package you're using.

Affected packages

Maven/org.elasticsearch.plugin:x-pack-security
Introduced in: 0Fixed in: 8.19.9
Fix# pom.xml: bump <version>8.19.9</version> for org.elasticsearch.plugin:x-pack-security
Maven/org.elasticsearch.plugin:x-pack-security
Introduced in: 9.0.0Fixed in: 9.1.9
Fix# pom.xml: bump <version>9.1.9</version> for org.elasticsearch.plugin:x-pack-security
Maven/org.elasticsearch.plugin:x-pack-security
Introduced in: 9.2.0Fixed in: 9.2.3
Fix# pom.xml: bump <version>9.2.3</version> for org.elasticsearch.plugin:x-pack-security

References