QID 730139
Date Published: 2021-08-31
QID 730139: Elasticsearch Denial of Service Vulnerability (ESA-2021-15)
Elasticsearch is a search server based on Lucene that provides a distributed, multitenant-capable full-text search engine with an HTTP web interface and schema-free JSON documents.
Affected with following vulnerability:
CVE-2021-22144: An uncontrolled recursion vulnerability that could lead to a denial of service attack was identified in the Elasticsearch Grok parser.
Affected Versions:
Elasticsearch versions prior to 7.13.3 and 6.8.17
QID detection logic:
Checks the vulnerable versions of ElasticSearch.
Successful exploitation of this vulnerability may allow an attacker with the ability to submit arbitrary queries to Elasticsearch could create a malicious Grok query that will crash the Elasticsearch node.
Solution
Customers are advised to upgrade to Elasticsearch version 7.13.3 or 6.8.17 to remediate this vulnerability.
Vendor References
- ESA-2021-15 -
www.elastic.co/community/security
CVEs related to QID 730139
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| ESA-2021-15 |
|