GHSA-wh6w-69xc-5rq5
Dashboard / Vulnerabilities / GHSA-wh6w-69xc-5rq5
GHSA-wh6w-69xc-5rq5
Summary: Improper Check for Unusual or Exceptional Conditions in Elasticsearch
Details: A Denial of Service flaw was discovered in Elasticsearch 8.0.0 through 8.2.0. Using this vulnerability, an unauthenticated attacker could forcibly shut down an Elasticsearch node with a specifically formatted network request. Version 8.2.1 contains a patch.
References: https://nvd.nist.gov/vuln/detail/CVE-2022-23712, https://discuss.elastic.co/t/elastic-stack-7-17-4-and-8-2-1-security-update/305530, https://github.com/elastic/elasticsearch, https://security.netapp.com/advisory/ntap-20220707-0010, https://www.elastic.co/community/security
Affected packages
Package
Name: org.elasticsearch:elasticsearch
Purl: pkg:maven/org.elasticsearch/elasticsearch
Affected ranges
Type: ECOSYSTEM
Events:
