Impact
Elasticsearch contains an uncontrolled recursion flaw that allows an authenticated user with read access to submit a deeply nested aggregation request. Processing this request triggers unbounded recursive calls, exhausting the node's memory and CPU, and causes the node to terminate. The process does not restart automatically, requiring manual intervention to restore service.
Affected Systems
Elasticsearch, by Elastic
Risk and Exploitability
The vulnerability receives a CVSS score of 6.5, indicating a moderate severity. Exploit probability data is not available and the flaw is not listed in CISA’s KEV catalog. The attack requires an authenticated user with the ability to use the search aggregation endpoint, typically over the cluster network. Once executed, the attacker can cause a local or remote denial of service without escalating privileges.
OpenCVE Enrichment