CVE-2021-22144

Description

In Elasticsearch versions before 7.13.3 and 6.8.17 an uncontrolled recursion vulnerability that could lead to a denial of service attack was identified in the Elasticsearch Grok parser. A user with the ability to submit arbitrary queries to Elasticsearch could create a malicious Grok query that will crash the Elasticsearch node.

Risk Information

Base Score
6.5
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
EPSS Score
Exploitation Probability
0.211

Associated Vulnerability

VulnerabilityOS Platform
Multiple vulnerabilities are affected in Oracle PeopleSoft Enterprise PeopleTools 8.58Windows
Multiple vulnerabilities are affected in Oracle PeopleSoft Enterprise PeopleTools 8.59Windows
Multiple vulnerabilities are affected in Oracle PeopleSoft Enterprise PeopleTools 8.60Windows
Vulnerabilities CVE-2021-22144 are fixed in Elasticsearch Core 6.8.17Windows
Vulnerabilities CVE-2021-22144 are fixed in Elasticsearch Core 7.13.3Windows
Vulnerabilities CVE-2021-22144 are fixed in Elasticsearch Core for Linux 6.8.17Linux
Vulnerabilities CVE-2021-22144 are fixed in Elasticsearch Core for Linux 7.13.3Linux
Uncontrolled Recursion Vulnerability (CVE-2021-22144)NCM

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234