CVE-2024-52979

Uncontrolled Resource Consumption in Elasticsearch while evaluating specifically crafted search templates with Mustache functions can lead to Denial of Service by causing the Elasticsearch node to crash.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:elastic:elasticsearch:*:*:*:*:*:*:*:*
cpe:2.3:a:elastic:elasticsearch:*:*:*:*:*:*:*:*

History

02 Oct 2025, 16:40

Type Values Removed Values Added
CPE cpe:2.3:a:elastic:elasticsearch:*:*:*:*:*:*:*:*
First Time Elastic elasticsearch
Elastic
References () https://discuss.elastic.co/t/elasticsearch-7-17-25-and-8-16-0-security-update-esa-2024-40/377709 - () https://discuss.elastic.co/t/elasticsearch-7-17-25-and-8-16-0-security-update-esa-2024-40/377709 - Patch, Vendor Advisory
Summary
  • (es) El consumo descontrolado de recursos en Elasticsearch al evaluar plantillas de búsqueda específicamente manipuladas con funciones Mustache puede provocar una denegación de servicio al provocar que el nodo Elasticsearch se bloquee.

01 May 2025, 14:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-05-01 14:15

Updated : 2025-10-02 16:40


NVD link : CVE-2024-52979

Mitre link : CVE-2024-52979

CVE.ORG link : CVE-2024-52979


JSON object : View

Products Affected

elastic

  • elasticsearch
CWE
CWE-400

Uncontrolled Resource Consumption