CVE-2022-38778

Source
https://cve.org/CVERecord?id=CVE-2022-38778
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-38778.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2022-38778
Published
2023-02-08T00:00:00Z
Modified
2026-08-12T13:33:40.855847Z
Severity
  • 6.5 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
[none]
Details

A flaw (CVE-2022-38900) was discovered in one of Kibana’s third party dependencies, that could allow an authenticated user to perform a request that crashes the Kibana server process.

Database specific
{
    "cna_assigner": "elastic",
    "cwe_ids": [
        "CWE-20"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/38xxx/CVE-2022-38778.json"
}
References

Affected packages

Git
github.com/elastic/elasticsearch

Affected ranges

Type
GIT
Repo
https://github.com/elastic/elasticsearch
Events
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "7.0.0"
        },
        {
            "fixed": "7.17.9"
        },
        {
            "introduced": "8.0.0"
        },
        {
            "fixed": "8.6.1"
        }
    ],
    "source": "CPE_RANGE",
    "cpe": "cpe:2.3:a:elastic:kibana:*:*:*:*:*:*:*:*"
}

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-38778.json"
vanir_signatures
[
    {
        "target": {
            "function": "readInt",
            "file": "server/src/main/java/org/elasticsearch/common/lucene/store/ByteArrayIndexInput.java"
        },
        "deprecated": false,
        "source": "https://github.com/elastic/elasticsearch/commit/180c9830da956993e59e2cd70eb32b5e383ea42c",
        "id": "CVE-2022-38778-180d5a29",
        "signature_version": "v1",
        "digest": {
            "length": 152.0,
            "function_hash": "10533168429402678403754680246021564806"
        },
        "signature_type": "Function"
    },
    {
        "target": {
            "function": "start",
            "file": "test/test-clusters/src/main/java/org/elasticsearch/test/cluster/local/LocalClusterFactory.java"
        },
        "deprecated": false,
        "source": "https://github.com/elastic/elasticsearch/commit/ef48222227ee6b9e70e502f0f0daa52435ee634d",
        "id": "CVE-2022-38778-7126c131",
        "signature_version": "v1",
        "digest": {
            "length": 796.0,
            "function_hash": "253424462771408036179652827713905704388"
        },
        "signature_type": "Function"
    },
    {
        "target": {
            "function": "readLong",
            "file": "server/src/main/java/org/elasticsearch/common/lucene/store/ByteArrayIndexInput.java"
        },
        "deprecated": false,
        "source": "https://github.com/elastic/elasticsearch/commit/180c9830da956993e59e2cd70eb32b5e383ea42c",
        "id": "CVE-2022-38778-7233f7e2",
        "signature_version": "v1",
        "digest": {
            "length": 150.0,
            "function_hash": "235217289820273404281378108466454239845"
        },
        "signature_type": "Function"
    },
    {
        "target": {
            "function": "randomReadAndSlice",
            "file": "test/framework/src/main/java/org/elasticsearch/common/lucene/store/ESIndexInputTestCase.java"
        },
        "deprecated": false,
        "source": "https://github.com/elastic/elasticsearch/commit/180c9830da956993e59e2cd70eb32b5e383ea42c",
        "id": "CVE-2022-38778-91a0c75c",
        "signature_version": "v1",
        "digest": {
            "length": 3514.0,
            "function_hash": "161786577891009899630378884859323635987"
        },
        "signature_type": "Function"
    },
    {
        "target": {
            "file": "test/framework/src/main/java/org/elasticsearch/common/lucene/store/ESIndexInputTestCase.java"
        },
        "deprecated": false,
        "source": "https://github.com/elastic/elasticsearch/commit/180c9830da956993e59e2cd70eb32b5e383ea42c",
        "id": "CVE-2022-38778-9e0fc8b5",
        "signature_version": "v1",
        "digest": {
            "threshold": 0.9,
            "line_hashes": [
                "156738400526554020086975403987478472997",
                "15972875792075159037435414562897514077",
                "92408852300593194682426392315542467083",
                "40184908099577937155472125875744383410",
                "333559055614489859966116854374310100005",
                "120301660886651824166787444676297401423",
                "63537114555770555568661762012645449832",
                "262008344941757258588690678409555959942",
                "164682725421451002274144122277549431332",
                "215024624280389234337012579520124601093",
                "236722858576933758223849191352864952949",
                "76652636609817784704603678582687013328",
                "83914357768742210919730025140242400251",
                "264114008540661592998784847684130575285",
                "284740451675268798513295990790770797303",
                "211761455285545379432187149256609063125",
                "146099296912450670243913856840529764534",
                "296098386072100179650173565873696421106",
                "214408256251475876627969192701336555012",
                "150682854112045851865642322218240435495",
                "102950571907770909551137626182100909775",
                "326357686230228773823518306607887105527",
                "279807211058590473712098630632970075219",
                "267110030013182417294707314330701596973",
                "13717028077378036133793498693235637646",
                "87186904964871225331789544667996345378",
                "99453392751741456978550248648531072366",
                "129428298889564249014862309817801122866",
                "308064566767855279269711721246708763611"
            ]
        },
        "signature_type": "Line"
    },
    {
        "target": {
            "file": "test/test-clusters/src/main/java/org/elasticsearch/test/cluster/local/LocalClusterFactory.java"
        },
        "deprecated": false,
        "source": "https://github.com/elastic/elasticsearch/commit/ef48222227ee6b9e70e502f0f0daa52435ee634d",
        "id": "CVE-2022-38778-adc0c667",
        "signature_version": "v1",
        "digest": {
            "threshold": 0.9,
            "line_hashes": [
                "328783117535713225377078719017895934894",
                "218962949926834068220532377964025986269",
                "238873534878858557428085250597699491727",
                "63077107520883219164804643621703692733",
                "66788853691360615475714774552204583495",
                "235984818079188790404255208318579500458",
                "122272605970820100222461377080912574433",
                "218240151183537112180691515958244680759",
                "74982244718916453758071782997683156102",
                "338998086836341997413146815199410074826",
                "183545008697450786058075772372139794156",
                "14150877025559646740082274151309028560",
                "165346515570815984485986167003908280712",
                "133921416539802914293419784636618607124",
                "335194391246084399905387481005122256392",
                "287472674007991101034770761473652905017",
                "32088835855662654741678314163880302816",
                "1737611290573491832151774625136018650",
                "41302012581605084517150417062557235387",
                "111850715464812135337423374498156388695",
                "190938082947915130398453485194117962279",
                "200222680760379930174317775945798073524"
            ]
        },
        "signature_type": "Line"
    },
    {
        "target": {
            "file": "server/src/main/java/org/elasticsearch/common/lucene/store/ByteArrayIndexInput.java"
        },
        "deprecated": false,
        "source": "https://github.com/elastic/elasticsearch/commit/180c9830da956993e59e2cd70eb32b5e383ea42c",
        "id": "CVE-2022-38778-b807f209",
        "signature_version": "v1",
        "digest": {
            "threshold": 0.9,
            "line_hashes": [
                "96071095236074608920723557767475676154",
                "84543064209429786306824376530333110203",
                "57923916179587267824469875345565469875",
                "146364694554752518922505076293318695270",
                "208603599721533178027875780823691638480",
                "117066245215813509173144299429705740269",
                "183499434658962346222140780574522505178",
                "172718764692006347154343753839076279292",
                "157559990685437885885005989358081710405",
                "339285447274199741301121962922226466738",
                "213597687138703438178535712922587243325",
                "113004493365379157357402979271672958910"
            ]
        },
        "signature_type": "Line"
    },
    {
        "target": {
            "function": "readShort",
            "file": "server/src/main/java/org/elasticsearch/common/lucene/store/ByteArrayIndexInput.java"
        },
        "deprecated": false,
        "source": "https://github.com/elastic/elasticsearch/commit/180c9830da956993e59e2cd70eb32b5e383ea42c",
        "id": "CVE-2022-38778-ba6cf0c2",
        "signature_version": "v1",
        "digest": {
            "length": 152.0,
            "function_hash": "152705162031613571382435460754849534423"
        },
        "signature_type": "Function"
    }
]
vanir_signatures_modified
"2026-08-12T13:33:40Z"
github.com/elastic/kibana

Affected ranges

Type
GIT
Repo
https://github.com/elastic/kibana
Events
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "7.0.0"
        },
        {
            "fixed": "7.17.9"
        },
        {
            "introduced": "8.0.0"
        },
        {
            "fixed": "8.6.1"
        }
    ],
    "source": "CPE_RANGE",
    "cpe": "cpe:2.3:a:elastic:kibana:*:*:*:*:*:*:*:*"
}

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-38778.json"
github.com/samverschueren/decode-uri-component

Affected ranges

Type
GIT
Repo
https://github.com/samverschueren/decode-uri-component
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "fixed": "0.2.1"
        }
    ],
    "source": "CPE_RANGE",
    "cpe": "cpe:2.3:a:decode-uri-component_project:decode-uri-component:*:*:*:*:*:node.js:*:*"
}

Affected versions

v0.*
v0.1.0
v0.2.0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-38778.json"