PT-2022-3398 · Elastic · Elasticsearch

Published

2022-06-06

·

Updated

2024-03-06

·

CVE-2022-23712

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Elasticsearch versions 8.0.0 through 8.2.0
Description A Denial of Service flaw was discovered in Elasticsearch, related to insufficient exception handling. This issue can be exploited by an unauthenticated attacker to shut down an Elasticsearch node using a specifically formatted network request.
Recommendations For versions 8.0.0 through 8.2.0, update to version 8.2.1 or later, which contains a patch for this issue. As a temporary workaround, consider restricting access to the Elasticsearch node to minimize the risk of exploitation.

Fix

DoS

Improper Check for Exceptional Conditions

Weakness Enumeration

Related Identifiers

BDU:2022-04170
BIT-ELASTICSEARCH-2022-23712
CVE-2022-23712
GHSA-WH6W-69XC-5RQ5

Affected Products

Elasticsearch