CyberRota Analysis
AI-GeneratedElasticsearch is vulnerable to an uncontrolled resource consumption issue that allows users with search privileges to submit specially crafted search requests, leading to excessive heap memory allocation. This can result in denial of service, causing node unavailability and overall cluster degradation, which may require manual intervention to restore functionality. Organizations utilizing Elasticsearch should prioritize addressing this vulnerability to prevent potential downtime and service disruptions.
Original NVD Description
Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead to denial of service via Excessive Allocation (CAPEC-130). A user with search privileges can submit a specially crafted search request that causes a data node to exhaust available heap memory, resulting in node unavailability and cluster degradation. An attacker could leverage this vulnerability to cause cluster downtime requiring manual intervention to restore service.
Related CVEs
Other vulnerabilities affecting the same vendor(s)