PT-2022-3398 · Elastic · Elasticsearch

CVE-2022-23712

·

Published

2022-06-06

·

Updated

2024-03-06

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Elasticsearch versions 8.0.0 through 8.2.0
Description A Denial of Service flaw was discovered in Elasticsearch, related to insufficient exception handling. This issue can be exploited by an unauthenticated attacker to shut down an Elasticsearch node using a specifically formatted network request.
Recommendations For versions 8.0.0 through 8.2.0, update to version 8.2.1 or later, which contains a patch for this issue. As a temporary workaround, consider restricting access to the Elasticsearch node to minimize the risk of exploitation.

Exploit

Fix

DoS

Improper Check for Exceptional Conditions

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2022-04170
BIT-ELASTICSEARCH-2022-23712
CVE-2022-23712
GHSA-WH6W-69XC-5RQ5

Affected Products

Elasticsearch