CVE-2022-23712: High severity elastic vulnerability
A Denial of Service flaw was discovered in Elasticsearch. Using this vulnerability, an unauthenticated attacker could forcibly shut down an Elasticsearch node with a specifically formatted network request.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-23712?
CVE-2022-23712 is a Denial of Service vulnerability in Elasticsearch that allows an unauthenticated attacker to shut down an Elasticsearch node with a specially crafted network request.
How does CVE-2022-23712 affect Elasticsearch?
CVE-2022-23712 affects Elasticsearch by allowing an unauthenticated attacker to forcibly shut down an Elasticsearch node with a specifically formatted network request.
What is the severity of CVE-2022-23712?
CVE-2022-23712 has a severity rating of high, with a score of 7.5.
Which versions of Elasticsearch are affected by CVE-2022-23712?
CVE-2022-23712 affects Elasticsearch versions 8.0.0 to 8.2.1.
How can I fix CVE-2022-23712?
To fix CVE-2022-23712, it is recommended to upgrade to a version of Elasticsearch that is not affected by the vulnerability.