CVE-2024-52979

Severity CVSS v4.0:
Pending analysis
Type:
CWE-400 Uncontrolled Resource Consumption ('Resource Exhaustion')
Publication date:
01/05/2025
Last modified:
02/10/2025

Description

Uncontrolled Resource Consumption in Elasticsearch while evaluating specifically crafted search templates with Mustache functions can lead to Denial of Service by causing the Elasticsearch node to crash.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:elastic:elasticsearch:*:*:*:*:*:*:*:* 7.17.25 (excluding)
cpe:2.3:a:elastic:elasticsearch:*:*:*:*:*:*:*:* 8.0.0 (including) 8.16.0 (excluding)