QID 995771
Date Published: 2023-11-01
QID 995771: Java (Maven) Security Update for org.elasticsearch:elasticsearch (GHSA-2cqf-6xv9-f22w)
An issue has been identified with how Elasticsearch handled incoming requests on the HTTP layer. An unauthenticated user could force an Elasticsearch node to exit with an OutOfMemory error by sending a moderate number of malformed HTTP requests. The issue was identified by Elastic Engineering and we have no indication that the issue is known or that it is being exploited in the wild.
Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.
Solution
Refer to Github security advisory GHSA-2cqf-6xv9-f22w for updates and patch information.
Vendor References
- GHSA-2cqf-6xv9-f22w -
github.com/advisories/GHSA-2cqf-6xv9-f22w
CVEs related to QID 995771
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-2cqf-6xv9-f22w | org.elasticsearch:elasticsearch |
|