First published: Mon Jul 26 2021(Updated: )
In Elasticsearch versions before 7.13.3 and 6.8.17 an uncontrolled recursion vulnerability that could lead to a denial of service attack was identified in the Elasticsearch Grok parser. A user with the ability to submit arbitrary queries to Elasticsearch could create a malicious Grok query that will crash the Elasticsearch node.
Credit: bressers@elastic.co
Affected Software | Affected Version | How to fix |
---|---|---|
Elastic Elasticsearch | <6.8.17 | |
Elastic Elasticsearch | >=7.0.0<7.13.3 | |
oracle communications Cloud native core automated test suite | =1.8.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-22144 is an uncontrolled recursion vulnerability in Elasticsearch versions before 7.13.3 and 6.8.17.
CVE-2021-22144 affects Elasticsearch versions before 7.13.3 and 6.8.17 by allowing an uncontrolled recursion vulnerability that could lead to a denial of service attack.
Users of Elasticsearch versions before 7.13.3 and 6.8.17 are affected by CVE-2021-22144.
The severity of CVE-2021-22144 is medium, with a CVSS score of 6.5.
To fix CVE-2021-22144, users should update to Elasticsearch versions 7.13.3 or 6.8.17.