9.5.0
16 years ago
7 days ago
Known vulnerabilities in the org.elasticsearch:elasticsearch package. This does not include vulnerabilities belonging to this package’s dependencies.
Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.
Fix for free| Vulnerability | Vulnerable Version |
|---|---|
org.elasticsearch:elasticsearch is a Distributed, RESTful Search Engine. Affected versions of this package are vulnerable to Allocation of Resources Without Limits or Throttling via the machine learning request process. An attacker can exhaust system memory and render the affected node unavailable by submitting specially crafted requests with elevated privileges. How to fix Allocation of Resources Without Limits or Throttling? Upgrade | [8.0.0-alpha1,8.19.17)[9.0.0-beta1,9.3.6)[9.4.0,9.4.3) |
org.elasticsearch:elasticsearch is a Distributed, RESTful Search Engine. Affected versions of this package are vulnerable to Uncontrolled Recursion in the How to fix Uncontrolled Recursion? Upgrade | [8.0.0-alpha1,8.19.17)[9.0.0-beta1,9.3.6)[9.4.0,9.4.3) |