# Elasticsearch 7.13.3 and 6.8.17 Security Update

**URL:** https://discuss.elastic.co/t/elasticsearch-7-13-3-and-6-8-17-security-update/278100
**Category:** Security Announcements
**Created:** [July 7, 2021, 5:23pm UTC](https://discuss.elastic.co/t/elasticsearch-7-13-3-and-6-8-17-security-update/278100 "2021-07-07T17:23:55Z")
**Posts on this page:** 1
**Showing post:** 1

<div class="post-metadata">

### Author: ![douglasday](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/douglasday/32/74044_2.png) [@douglasday](https://discuss.elastic.co/u/douglasday)
#### Post date: [July 7, 2021, 5:23pm UTC](https://discuss.elastic.co/t/elasticsearch-7-13-3-and-6-8-17-security-update/278100/1 "2021-07-07T17:23:56Z")

</div>

**Elasticsearch Denial of Service issue (ESA-2021-15)**

An uncontrolled recursion vulnerability that could lead to a denial of service attack was identified in the Elasticsearch Grok parser. A user with the ability to submit arbitrary queries to Elasticsearch could create a malicious Grok query that will crash the Elasticsearch node.

**Affected Versions:**

Elasticsearch versions prior to 7.13.3 and 6.8.17

**Solutions and Mitigations:**

Users should update their version of Elasticsearch to 7.13.3 or 6.8.17.

**CVSSv3:** 5.7 - AV:A/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

**CVE ID:** CVE-2021-22144

**CWE:** CWE-674: Uncontrolled Recursion

---

_[View the full topic](https://discuss.elastic.co/t/elasticsearch-7-13-3-and-6-8-17-security-update/278100)._
