QID 981383
QID 981383: Java (maven) Security Update for org.elasticsearch:elasticsearch (GHSA-3393-hvrj-w7v3)
In Elasticsearch versions before 7.13.3 and 6.8.17 an uncontrolled recursion vulnerability that could lead to a denial of service attack was identified in the Elasticsearch Grok parser. A user with the ability to submit arbitrary queries to Elasticsearch could create a malicious Grok query that will crash the Elasticsearch node.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-3393-hvrj-w7v3 for updates pertaining to this vulnerability.
Vendor References
- GHSA-3393-hvrj-w7v3 -
github.com/advisories/GHSA-3393-hvrj-w7v3
CVEs related to QID 981383
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-3393-hvrj-w7v3 | org.elasticsearch:elasticsearch |
|