Elastic Elasticsearch
cpe:2.3:a:elastic:elasticsearch:*:*:*:*:*:*:*
- ~7
- ~8.0.0, <= 8.19.8
- ~9.0.0, <= 9.1.8
- ~9.2.0, <= 9.2.2
A vulnerability allowing excessive resource allocation has been identified in Elasticsearch. This issue can be exploited by low-privileged authenticated users who submit oversized user settings data, causing out-of-memory crashes and persistent denial-of-service conditions. The vulnerability arises from the application's lack of limits or throttling on resource allocation.
Exploitation of this vulnerability leads to a denial-of-service condition, causing the application to crash due to out-of-memory errors.
Users can upgrade to Elasticsearch versions 8.19.9, 9.1.9, or 9.2.3 to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.