In Elasticsearch versions before 7.13.3 and 6.8.17 an uncontrolled recursion vulnerability that could lead to a denial of service attack was identified in the Elasticsearch Grok parser. A user with the ability to submit arbitrary queries to Elasticsearch could create a malicious Grok query that will crash the Elasticsearch node.
{
"nvd_published_at": "2021-07-26T12:15:00Z",
"cwe_ids": [
"CWE-674"
],
"severity": "MODERATE",
"github_reviewed": true,
"github_reviewed_at": "2021-08-02T19:21:25Z"
}