CVE-2024-37280: Elasticsearch StackOverflow vulnerability

Published Jun 13, 2024
·
Updated

A flaw was discovered in Elasticsearch, affecting document ingestion when an index template contains a dynamic field mapping of “passthrough” type. Under certain circumstances, ingesting documents in this index would cause a StackOverflow exception to be thrown and ultimately lead to a Denial of Service. Note that passthrough fields is an experimental feature.

Affected Software

2 affected componentsFixes available
maven/org.elasticsearch:elasticsearch>=8.13.1<8.14.0
8.14.0
Elastic Elasticsearch>=8.13.1<8.14.0

Event History

Jun 13, 2024
CVE Published
via MITRE·04:26 PM
Data Sourced
via MITRE·04:26 PM
DescriptionSeverityWeakness
Advisory Published
via GitHub·06:31 PM

Frequently Asked Questions

1

What is the severity of CVE-2024-37280?

CVE-2024-37280 is classified as a high severity vulnerability due to its potential to cause a StackOverflow exception during document ingestion.

2

How do I fix CVE-2024-37280?

To mitigate CVE-2024-37280, update Elasticsearch to version 8.14.0 or higher, ensuring dynamic field mappings do not include 'passthrough' types in index templates.

3

Who is affected by CVE-2024-37280?

CVE-2024-37280 affects Elasticsearch versions between 8.13.1 and 8.14.0.

4

What is the risk of using affected versions for CVE-2024-37280?

Using affected versions of Elasticsearch may lead to application crashes or denial of service due to the StackOverflow exceptions.

5

What actions should organizations take regarding CVE-2024-37280?

Organizations should assess their current Elasticsearch versions and prioritize updating to the fixed version to prevent exploitation of CVE-2024-37280.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203