CVE-2025-68390
ADVISORY - githubSummary
Allocation of Resources Without Limits or Throttling (CWE-770) in Elasticsearch can allow an authenticated user with snapshot restore privileges to cause Excessive Allocation (CAPEC-130) of memory and a denial of service (DoS) via crafted HTTP request.
Common Weakness Enumeration (CWE)
Allocation of Resources Without Limits or Throttling
Allocation of Resources Without Limits or Throttling
Allocation of Resources Without Limits or Throttling
NIST
1.2
CVSS SCORE
4.9mediumGitHub
1.2
CVSS SCORE
4.9mediumUbuntu
-
CVSS SCORE
N/AmediumBitnami
BIT-elasticsearch-2025-68390
1.2
CVSS SCORE
4.9mediumRed Hat
1.2
CVSS SCORE
4.9mediumChainguard
CGA-2f2h-ccww-h47h
-
Chainguard
CGA-3h2j-qxfj-q4pv
-
Chainguard
CGA-3vx6-q5qp-m6rf
-
Chainguard
CGA-8c58-5whr-g66c
-
Chainguard
CGA-ppjr-xg6m-j5q7
-
minimos
MINI-2c5m-993x-qm5c
-
minimos
MINI-5xfv-mxrp-2398
-
minimos
MINI-6rcv-3f27-mm2c
-
minimos
MINI-6w7c-q497-w62r
-
minimos
MINI-792f-qvxj-w9vg
-
minimos
MINI-89hp-c6x4-7rjg
-
minimos
MINI-9rvg-qpvg-hhr9
-
minimos
MINI-g3fh-8cvg-fx39
-
minimos
MINI-pccj-g5qh-mhwm
-
minimos
MINI-q65h-hq3h-pgm7
-
minimos
MINI-qwq2-mxfj-p482
-
minimos
MINI-wvc9-cqfp-7825
-
minimos
MINI-x84v-3g64-q5gq
-