A flaw (CVE-2022-38900) was discovered in one of Kibana’s third party dependencies, that could allow an authenticated user to perform a request that crashes the Kibana server process.
{
"cna_assigner": "elastic",
"cwe_ids": [
"CWE-20"
],
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/38xxx/CVE-2022-38778.json"
}"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-38778.json"
[
{
"target": {
"function": "readInt",
"file": "server/src/main/java/org/elasticsearch/common/lucene/store/ByteArrayIndexInput.java"
},
"deprecated": false,
"source": "https://github.com/elastic/elasticsearch/commit/180c9830da956993e59e2cd70eb32b5e383ea42c",
"id": "CVE-2022-38778-180d5a29",
"signature_version": "v1",
"digest": {
"length": 152.0,
"function_hash": "10533168429402678403754680246021564806"
},
"signature_type": "Function"
},
{
"target": {
"function": "start",
"file": "test/test-clusters/src/main/java/org/elasticsearch/test/cluster/local/LocalClusterFactory.java"
},
"deprecated": false,
"source": "https://github.com/elastic/elasticsearch/commit/ef48222227ee6b9e70e502f0f0daa52435ee634d",
"id": "CVE-2022-38778-7126c131",
"signature_version": "v1",
"digest": {
"length": 796.0,
"function_hash": "253424462771408036179652827713905704388"
},
"signature_type": "Function"
},
{
"target": {
"function": "readLong",
"file": "server/src/main/java/org/elasticsearch/common/lucene/store/ByteArrayIndexInput.java"
},
"deprecated": false,
"source": "https://github.com/elastic/elasticsearch/commit/180c9830da956993e59e2cd70eb32b5e383ea42c",
"id": "CVE-2022-38778-7233f7e2",
"signature_version": "v1",
"digest": {
"length": 150.0,
"function_hash": "235217289820273404281378108466454239845"
},
"signature_type": "Function"
},
{
"target": {
"function": "randomReadAndSlice",
"file": "test/framework/src/main/java/org/elasticsearch/common/lucene/store/ESIndexInputTestCase.java"
},
"deprecated": false,
"source": "https://github.com/elastic/elasticsearch/commit/180c9830da956993e59e2cd70eb32b5e383ea42c",
"id": "CVE-2022-38778-91a0c75c",
"signature_version": "v1",
"digest": {
"length": 3514.0,
"function_hash": "161786577891009899630378884859323635987"
},
"signature_type": "Function"
},
{
"target": {
"file": "test/framework/src/main/java/org/elasticsearch/common/lucene/store/ESIndexInputTestCase.java"
},
"deprecated": false,
"source": "https://github.com/elastic/elasticsearch/commit/180c9830da956993e59e2cd70eb32b5e383ea42c",
"id": "CVE-2022-38778-9e0fc8b5",
"signature_version": "v1",
"digest": {
"threshold": 0.9,
"line_hashes": [
"156738400526554020086975403987478472997",
"15972875792075159037435414562897514077",
"92408852300593194682426392315542467083",
"40184908099577937155472125875744383410",
"333559055614489859966116854374310100005",
"120301660886651824166787444676297401423",
"63537114555770555568661762012645449832",
"262008344941757258588690678409555959942",
"164682725421451002274144122277549431332",
"215024624280389234337012579520124601093",
"236722858576933758223849191352864952949",
"76652636609817784704603678582687013328",
"83914357768742210919730025140242400251",
"264114008540661592998784847684130575285",
"284740451675268798513295990790770797303",
"211761455285545379432187149256609063125",
"146099296912450670243913856840529764534",
"296098386072100179650173565873696421106",
"214408256251475876627969192701336555012",
"150682854112045851865642322218240435495",
"102950571907770909551137626182100909775",
"326357686230228773823518306607887105527",
"279807211058590473712098630632970075219",
"267110030013182417294707314330701596973",
"13717028077378036133793498693235637646",
"87186904964871225331789544667996345378",
"99453392751741456978550248648531072366",
"129428298889564249014862309817801122866",
"308064566767855279269711721246708763611"
]
},
"signature_type": "Line"
},
{
"target": {
"file": "test/test-clusters/src/main/java/org/elasticsearch/test/cluster/local/LocalClusterFactory.java"
},
"deprecated": false,
"source": "https://github.com/elastic/elasticsearch/commit/ef48222227ee6b9e70e502f0f0daa52435ee634d",
"id": "CVE-2022-38778-adc0c667",
"signature_version": "v1",
"digest": {
"threshold": 0.9,
"line_hashes": [
"328783117535713225377078719017895934894",
"218962949926834068220532377964025986269",
"238873534878858557428085250597699491727",
"63077107520883219164804643621703692733",
"66788853691360615475714774552204583495",
"235984818079188790404255208318579500458",
"122272605970820100222461377080912574433",
"218240151183537112180691515958244680759",
"74982244718916453758071782997683156102",
"338998086836341997413146815199410074826",
"183545008697450786058075772372139794156",
"14150877025559646740082274151309028560",
"165346515570815984485986167003908280712",
"133921416539802914293419784636618607124",
"335194391246084399905387481005122256392",
"287472674007991101034770761473652905017",
"32088835855662654741678314163880302816",
"1737611290573491832151774625136018650",
"41302012581605084517150417062557235387",
"111850715464812135337423374498156388695",
"190938082947915130398453485194117962279",
"200222680760379930174317775945798073524"
]
},
"signature_type": "Line"
},
{
"target": {
"file": "server/src/main/java/org/elasticsearch/common/lucene/store/ByteArrayIndexInput.java"
},
"deprecated": false,
"source": "https://github.com/elastic/elasticsearch/commit/180c9830da956993e59e2cd70eb32b5e383ea42c",
"id": "CVE-2022-38778-b807f209",
"signature_version": "v1",
"digest": {
"threshold": 0.9,
"line_hashes": [
"96071095236074608920723557767475676154",
"84543064209429786306824376530333110203",
"57923916179587267824469875345565469875",
"146364694554752518922505076293318695270",
"208603599721533178027875780823691638480",
"117066245215813509173144299429705740269",
"183499434658962346222140780574522505178",
"172718764692006347154343753839076279292",
"157559990685437885885005989358081710405",
"339285447274199741301121962922226466738",
"213597687138703438178535712922587243325",
"113004493365379157357402979271672958910"
]
},
"signature_type": "Line"
},
{
"target": {
"function": "readShort",
"file": "server/src/main/java/org/elasticsearch/common/lucene/store/ByteArrayIndexInput.java"
},
"deprecated": false,
"source": "https://github.com/elastic/elasticsearch/commit/180c9830da956993e59e2cd70eb32b5e383ea42c",
"id": "CVE-2022-38778-ba6cf0c2",
"signature_version": "v1",
"digest": {
"length": 152.0,
"function_hash": "152705162031613571382435460754849534423"
},
"signature_type": "Function"
}
]
"2026-08-12T13:33:40Z"
{
"extracted_events": [
{
"introduced": "0"
},
{
"fixed": "0.2.1"
}
],
"source": "CPE_RANGE",
"cpe": "cpe:2.3:a:decode-uri-component_project:decode-uri-component:*:*:*:*:*:node.js:*:*"
}