CVE-2022-38778

Source
https://nvd.nist.gov/vuln/detail/CVE-2022-38778
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-38778.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2022-38778
Published
2023-02-08T21:15:10.583Z
Modified
2025-12-09T17:02:53.244283Z
Severity
  • 6.5 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
[none]
Details

A flaw (CVE-2022-38900) was discovered in one of Kibana’s third party dependencies, that could allow an authenticated user to perform a request that crashes the Kibana server process.

References

Affected packages

Git

github.com/elastic/elasticsearch

Affected ranges

Type
GIT
Repo
https://github.com/elastic/elasticsearch
Events

Database specific

source

"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-38778.json"

vanir_signatures

[
    {
        "deprecated": false,
        "id": "CVE-2022-38778-7126c131",
        "digest": {
            "length": 796.0,
            "function_hash": "253424462771408036179652827713905704388"
        },
        "source": "https://github.com/elastic/elasticsearch/commit/ef48222227ee6b9e70e502f0f0daa52435ee634d",
        "signature_version": "v1",
        "signature_type": "Function",
        "target": {
            "file": "test/test-clusters/src/main/java/org/elasticsearch/test/cluster/local/LocalClusterFactory.java",
            "function": "start"
        }
    },
    {
        "deprecated": false,
        "id": "CVE-2022-38778-adc0c667",
        "digest": {
            "threshold": 0.9,
            "line_hashes": [
                "328783117535713225377078719017895934894",
                "218962949926834068220532377964025986269",
                "238873534878858557428085250597699491727",
                "63077107520883219164804643621703692733",
                "66788853691360615475714774552204583495",
                "235984818079188790404255208318579500458",
                "122272605970820100222461377080912574433",
                "218240151183537112180691515958244680759",
                "74982244718916453758071782997683156102",
                "338998086836341997413146815199410074826",
                "183545008697450786058075772372139794156",
                "14150877025559646740082274151309028560",
                "165346515570815984485986167003908280712",
                "133921416539802914293419784636618607124",
                "335194391246084399905387481005122256392",
                "287472674007991101034770761473652905017",
                "32088835855662654741678314163880302816",
                "1737611290573491832151774625136018650",
                "41302012581605084517150417062557235387",
                "111850715464812135337423374498156388695",
                "190938082947915130398453485194117962279",
                "200222680760379930174317775945798073524"
            ]
        },
        "source": "https://github.com/elastic/elasticsearch/commit/ef48222227ee6b9e70e502f0f0daa52435ee634d",
        "signature_version": "v1",
        "signature_type": "Line",
        "target": {
            "file": "test/test-clusters/src/main/java/org/elasticsearch/test/cluster/local/LocalClusterFactory.java"
        }
    }
]

github.com/elastic/kibana

Affected ranges

Type
GIT
Repo
https://github.com/elastic/kibana
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed

Database specific

source

"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-38778.json"

github.com/samverschueren/decode-uri-component

Affected ranges

Type
GIT
Repo
https://github.com/samverschueren/decode-uri-component
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed

Affected versions

v0.*

v0.1.0
v0.2.0

Database specific

source

"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-38778.json"