Resource exhaustion in Elasticsearch - CVE-2021-22144
Published: July 9, 2021
Vulnerability identifier: #VU54639
CSH Severity: Medium
CVSS v4: 8.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H]
CVE-ID: CVE-2021-22144
CWE-ID: CWE-400
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to an uncontrolled recursion issue in the Elasticsearch Grok parser. A remote authenticated attacker can trigger resource exhaustion and perform a denial of service (DoS) attack.
Affected software
Elasticsearch
PeopleSoft Enterprise PeopleTools
Operations Dashboard
Netcool Operations Insight
Junos Space Security Director
PeopleSoft Enterprise PeopleTools
Operations Dashboard
Netcool Operations Insight
Junos Space Security Director
How to mitigate CVE-2021-22144
Install updates from vendor's website.
Elasticsearch - addressed in versions 6.8.17, 7.13.3
Operations Dashboard - addressed in versions 2020.4.1-3, 2021.3.1
Netcool Operations Insight - update to 1.6.6
Junos Space Security Director - update to 24.1R3
Operations Dashboard - addressed in versions 2020.4.1-3, 2021.3.1
Netcool Operations Insight - update to 1.6.6
Junos Space Security Director - update to 24.1R3