CVE-2021-22144
26.07.2021, 12:15
In Elasticsearch versions before 7.13.3 and 6.8.17 an uncontrolled recursion vulnerability that could lead to a denial of service attack was identified in the Elasticsearch Grok parser. A user with the ability to submit arbitrary queries to Elasticsearch could create a malicious Grok query that will crash the Elasticsearch node.Enginsight
| Vendor | Product | Version |
|---|---|---|
| elastic | elasticsearch | 𝑥 < 6.8.17 |
| elastic | elasticsearch | 7.0.0 ≤ 𝑥 < 7.13.3 |
| oracle | communications_cloud_native_core_automated_test_suite | 1.8.0 |
𝑥
= Vulnerable software versions
Ubuntu Releases
Common Weakness Enumeration
References