Impact
The vulnerability is an uncontrolled recursion flaw that allows an authenticated user with low privileges to trigger the termination of an Elasticsearch node. This results in a denial of service by disrupting cluster availability. The flaw is classified as CWE-674 and is a manifestation of Excessive Allocation, which can cause the system to exhaust resources or crash.
Affected Systems
Elastic’s Elasticsearch product is affected. No specific version information is provided in the current data, so all deployed instances of Elasticsearch should be considered potentially impacted until the vendor’s update status is confirmed.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity. The EPSS score is not available, so the likelihood of exploitation cannot be quantified. The vulnerability is not listed in the CISA KEV catalog. Attack is likely through an authenticated session with low privileges, inferred from the description.
OpenCVE Enrichment