In Elasticsearch versions before 7.13.3 and 6.8.17 an uncontrolled recursion vulnerability that could lead to a denial of service attack was identified in the Elasticsearch Grok parser. A user with the ability to submit arbitrary queries to Elasticsearch could create a malicious Grok query that will crash the Elasticsearch node.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: elastic
Published: 2021-07-26T11:48:40
Updated: 2024-08-03T18:37:17.733Z
Reserved: 2021-01-04T00:00:00
Link: CVE-2021-22144
Vulnrichment
No data.
NVD
Status : Analyzed
Published: 2021-07-26T12:15:08.547
Modified: 2022-05-10T18:02:50.073
Link: CVE-2021-22144
Redhat