Improper Check for Unusual or Exceptional Conditions in Elasticsearch - CVE-2022-23712

 

Improper Check for Unusual or Exceptional Conditions in Elasticsearch - CVE-2022-23712

Published: July 4, 2022


Vulnerability identifier: #VU64866
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-23712
CWE-ID: CWE-754
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to improper error handling. A remote attacker can send specifically formatted network request to the application and forcibly shut down an Elasticsearch node.


Affected software

Elasticsearch
IBM Cloud Pak for Business Automation

How to mitigate CVE-2022-23712

Install updates from vendor's website.

Elasticsearch - update to 8.2.1

External References

Related Security Bulletins