QID 995771

Date Published: 2023-11-01

QID 995771: Java (Maven) Security Update for org.elasticsearch:elasticsearch (GHSA-2cqf-6xv9-f22w)

An issue has been identified with how Elasticsearch handled incoming requests on the HTTP layer. An unauthenticated user could force an Elasticsearch node to exit with an OutOfMemory error by sending a moderate number of malformed HTTP requests. The issue was identified by Elastic Engineering and we have no indication that the issue is known or that it is being exploited in the wild.

Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.

  • CVSS V3 rated as High - 7.5 severity.
  • CVSS V2 rated as Medium - 5.4 severity.
  • Solution
    Refer to Github security advisory GHSA-2cqf-6xv9-f22w for updates and patch information.
    Vendor References

    CVEs related to QID 995771

    Software Advisories
    Advisory ID Software Component Link
    GHSA-2cqf-6xv9-f22w org.elasticsearch:elasticsearch URL Logo github.com/advisories/GHSA-2cqf-6xv9-f22w