Elastic Elasticsearch
cpe:2.3:a:elastic:elasticsearch:*:*:*:*:*:*:*
- <= 7.17.21
- <= 8.13.3
A resource allocation vulnerability without proper limits or throttling has been identified in Elasticsearch. This issue is present in versions prior to 7.17.21 and prior to 8.13.3. When exploited through a specially crafted query using an SQL function, the vulnerability can cause an OutOfMemoryError exception, leading to a crash.
Exploitation of this vulnerability causes a denial-of-service condition, where the application crashes due to memory exhaustion.
Users can upgrade to Elasticsearch versions 7.17.21 or 8.13.3 to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.