Allocation of Resources Without Limits or Throttling (CWE-770) in Elasticsearch can lead to a denial of service via Excessive Allocation (CAPEC-130). A user with elevated privileges can submit a specially crafted request that causes excessive memory consumption, which may render the affected node unavailable.
Attack Parameters
Impact Assessment
CVSS Vector v3.1
Weakness Type (CWE)
Vulnerable Products 2
| Configuration | From (including) | Up to (excluding) |
|---|---|---|
|
Elastic Elasticsearch
cpe:2.3:a:elastic:elasticsearch:*:*:*:*:*:*:*:*
|
8.0.0
|
8.19.20
|
|
Elastic Elasticsearch
cpe:2.3:a:elastic:elasticsearch:*:*:*:*:*:*:*:*
|
9.0.0
|
9.3.0
|