A flaw was discovered in Elasticsearch, where a large recursion using the innerForbidCircularReferences function of the PatternBank class could cause the Elasticsearch node to crash. A successful attack requires a malicious user to have read_pipeline Elasticsearch cluster privilege assigned to them.
| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| org.elasticsearch:elasticsearch(Maven) | 7.17.0 | 8.15.1 | N/A |
CVSS Metrics