Elastic Elasticsearch
cpe:2.3:a:elastic:elasticsearch:*:*:*:*:*:*:*
- ~7
- ~8.0.0, <= 8.19.7
- ~9.0.0, <= 9.1.7
- ~9.2.0, <= 9.2.1
A vulnerability allowing excessive memory allocation has been identified in Elasticsearch. This issue arises from the allocation of resources without limits or throttling, and can be exploited by an authenticated user with snapshot restore privileges. The vulnerability allows for crafted HTTP requests to cause excessive memory use, leading to a denial-of-service condition.
Exploitation of this vulnerability causes excessive memory consumption, leading to a denial-of-service condition where the application becomes unresponsive or unavailable.
Users can upgrade to Elasticsearch versions 8.19.8, 9.1.8, or 9.2.2 to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.