CVE-2024-52980

A flaw was discovered in Elasticsearch, where a large recursion using the innerForbidCircularReferences function of the PatternBank class could cause the Elasticsearch node to crash. A successful attack requires a malicious user to have read_pipeline Elasticsearch cluster privilege assigned to them.
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:elastic:elasticsearch:*:*:*:*:*:*:*:*

History

30 Sep 2025, 21:35

Type Values Removed Values Added
First Time Elastic elasticsearch
Elastic
CPE cpe:2.3:a:elastic:elasticsearch:*:*:*:*:*:*:*:*
References () https://discuss.elastic.co/t/elasticsearch-8-15-1-security-update-esa-2024-34/376919 - () https://discuss.elastic.co/t/elasticsearch-8-15-1-security-update-esa-2024-34/376919 - Patch, Issue Tracking, Vendor Advisory
Summary
  • (es) Se descubrió una falla en Elasticsearch. Una recursión extensa con la función innerForbidCircularReferences de la clase PatternBank podía provocar el bloqueo del nodo Elasticsearch. Para que el ataque tenga éxito, se requiere que un usuario malintencionado tenga asignado el privilegio read_pipeline del clúster de Elasticsearch.

08 Apr 2025, 17:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-04-08 17:15

Updated : 2025-09-30 21:35


NVD link : CVE-2024-52980

Mitre link : CVE-2024-52980

CVE.ORG link : CVE-2024-52980


JSON object : View

Products Affected

elastic

  • elasticsearch
CWE
CWE-400

Uncontrolled Resource Consumption