First published: Mon Jun 06 2022(Updated: )
A Denial of Service flaw was discovered in Elasticsearch. Using this vulnerability, an unauthenticated attacker could forcibly shut down an Elasticsearch node with a specifically formatted network request.
Credit: bressers@elastic.co
Affected Software | Affected Version | How to fix |
---|---|---|
Elastic Elasticsearch | >=8.0.0<8.2.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-23712 is a Denial of Service vulnerability in Elasticsearch that allows an unauthenticated attacker to shut down an Elasticsearch node with a specially crafted network request.
CVE-2022-23712 affects Elasticsearch by allowing an unauthenticated attacker to forcibly shut down an Elasticsearch node with a specifically formatted network request.
CVE-2022-23712 has a severity rating of high, with a score of 7.5.
CVE-2022-23712 affects Elasticsearch versions 8.0.0 to 8.2.1.
To fix CVE-2022-23712, it is recommended to upgrade to a version of Elasticsearch that is not affected by the vulnerability.