Related Vulnerabilities: CVE-2022-23712  

A Denial of Service flaw was discovered in Elasticsearch. Using this vulnerability, an unauthenticated attacker could forcibly shut down an Elasticsearch node with a specifically formatted network request.

Description

The MITRE CVE dictionary describes this issue as:

A Denial of Service flaw was discovered in Elasticsearch. Using this vulnerability, an unauthenticated attacker could forcibly shut down an Elasticsearch node with a specifically formatted network request.

Additional Information

  • Bugzilla 2094515: CVE-2022-23712 elasticsearch: DoS via a specifically formatted network request
  • CWE-754: Improper Check for Unusual or Exceptional Conditions
  • FAQ: Frequently asked questions about CVE-2022-23712