CVE-2021-22144
Description
In Elasticsearch versions before 7.13.3 and 6.8.17 an uncontrolled recursion vulnerability that could lead to a denial of service attack was identified in the Elasticsearch Grok parser. A user with the ability to submit arbitrary queries to Elasticsearch could create a malicious Grok query that will crash the Elasticsearch node.
Risk Information
Base Score
6.5
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
EPSS Score
Exploitation Probability
0.211
Associated Vulnerability
| Vulnerability | OS Platform |
|---|---|
| Multiple vulnerabilities are affected in Oracle PeopleSoft Enterprise PeopleTools 8.58 | Windows |
| Multiple vulnerabilities are affected in Oracle PeopleSoft Enterprise PeopleTools 8.59 | Windows |
| Multiple vulnerabilities are affected in Oracle PeopleSoft Enterprise PeopleTools 8.60 | Windows |
| Vulnerabilities CVE-2021-22144 are fixed in Elasticsearch Core 6.8.17 | Windows |
| Vulnerabilities CVE-2021-22144 are fixed in Elasticsearch Core 7.13.3 | Windows |
| Vulnerabilities CVE-2021-22144 are fixed in Elasticsearch Core for Linux 6.8.17 | Linux |
| Vulnerabilities CVE-2021-22144 are fixed in Elasticsearch Core for Linux 7.13.3 | Linux |
| Uncontrolled Recursion Vulnerability (CVE-2021-22144) | NCM |
Patch Details
No records foundReferences
https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234