CVE-2024-52980

A flaw was discovered in Elasticsearch, where a large recursion using the innerForbidCircularReferences function of the PatternBank class could cause the Elasticsearch node to crash. A successful attack requires a malicious user to have read_pipeline Elasticsearch cluster privilege assigned to them.
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:elastic:elasticsearch:*:*:*:*:*:*:*:*

History

30 Sep 2025, 21:35

Type Values Removed Values Added
References () https://discuss.elastic.co/t/elasticsearch-8-15-1-security-update-esa-2024-34/376919 - () https://discuss.elastic.co/t/elasticsearch-8-15-1-security-update-esa-2024-34/376919 - Patch, Issue Tracking, Vendor Advisory
Summary
  • (es) Se descubrió una falla en Elasticsearch. Una recursión extensa con la función innerForbidCircularReferences de la clase PatternBank podía provocar el bloqueo del nodo Elasticsearch. Para que el ataque tenga éxito, se requiere que un usuario malintencionado tenga asignado el privilegio read_pipeline del clúster de Elasticsearch.
CPE cpe:2.3:a:elastic:elasticsearch:*:*:*:*:*:*:*:*
First Time Elastic elasticsearch
Elastic

08 Apr 2025, 17:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-04-08 17:15

Updated : 2025-09-30 21:35


NVD link : CVE-2024-52980

Mitre link : CVE-2024-52980

CVE.ORG link : CVE-2024-52980


JSON object : View

Products Affected

elastic

  • elasticsearch
CWE
CWE-400

Uncontrolled Resource Consumption