VDB
Sign up
MEDIUM4.9

GHSA-w5gg-2q56-6h4f

Elasticsearch Uncontrolled Resource Consumption vulnerability

Quick fix

GHSA-w5gg-2q56-6h4f — org.elasticsearch:elasticsearch: upgrade to the fixed version with the command below.

# pom.xml: bump <version>7.17.19</version> for org.elasticsearch:elasticsearch

Details

A flaw was discovered in Elasticsearch, where processing a document in a deeply nested pipeline on an ingest node could cause the Elasticsearch node to crash.

Are you affected?

Enter the version of the package you're using.

Affected packages

Maven/org.elasticsearch:elasticsearch
Introduced in: 7.0.0Fixed in: 7.17.19
Fix# pom.xml: bump <version>7.17.19</version> for org.elasticsearch:elasticsearch
Maven/org.elasticsearch:elasticsearch
Introduced in: 8.0.0Fixed in: 8.13.0
Fix# pom.xml: bump <version>8.13.0</version> for org.elasticsearch:elasticsearch

References