CVE-2025-68384
ADVISORY - githubSummary
Allocation of Resources Without Limits or Throttling (CWE-770) in Elasticsearch can allow a low-privileged authenticated user to cause Excessive Allocation (CAPEC-130) causing a persistent denial of service (OOM crash) via submission of oversized user settings data.
Common Weakness Enumeration (CWE)
Allocation of Resources Without Limits or Throttling
Allocation of Resources Without Limits or Throttling
Allocation of Resources Without Limits or Throttling
NIST
2.8
CVSS SCORE
6.5mediumGitHub
2.8
CVSS SCORE
6.5mediumUbuntu
-
CVSS SCORE
N/AmediumBitnami
BIT-elasticsearch-2025-68384
2.8
CVSS SCORE
6.5mediumRed Hat
2.8
CVSS SCORE
6.5mediumChainguard
CGA-33pw-jrqr-r7fh
-
Chainguard
CGA-3p5r-35jf-j862
-
Chainguard
CGA-cm5q-6cw5-c2ch
-
Chainguard
CGA-r23c-p68q-p477
-
minimos
MINI-286g-jp22-c5j7
-
minimos
MINI-384j-2vc8-rcfj
-
minimos
MINI-42hw-8mvh-pr99
-
minimos
MINI-4jhh-34xg-v3q2
-
minimos
MINI-739j-4m9m-rxjg
-
minimos
MINI-8vv6-8gh5-73mh
-
minimos
MINI-9x23-x6jh-7r8w
-
minimos
MINI-g7g4-gm9q-q2wm
-
minimos
MINI-mgpx-wq58-x73q
-
minimos
MINI-p529-vjhp-m2m4
-
minimos
MINI-qhx6-4f3w-g6cv
-
minimos
MINI-vhxv-228j-prw4
-
minimos
MINI-x98j-r39w-j6gv
-