CWE
122 787
Advisory Published
Advisory Published
Updated

CVE-2024-37280: Elasticsearch StackOverflow vulnerability

First published: Thu Jun 13 2024(Updated: )

A flaw was discovered in Elasticsearch, affecting document ingestion when an index template contains a dynamic field mapping of “passthrough” type. Under certain circumstances, ingesting documents in this index would cause a StackOverflow exception to be thrown and ultimately lead to a Denial of Service. Note that passthrough fields is an experimental feature.

Credit: bressers@elastic.co bressers@elastic.co

Affected SoftwareAffected VersionHow to fix
maven/org.elasticsearch:elasticsearch>=8.13.1<8.14.0
8.14.0
Elastic>=8.13.1<8.14.0

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Frequently Asked Questions

  • What is the severity of CVE-2024-37280?

    CVE-2024-37280 is classified as a high severity vulnerability due to its potential to cause a StackOverflow exception during document ingestion.

  • How do I fix CVE-2024-37280?

    To mitigate CVE-2024-37280, update Elasticsearch to version 8.14.0 or higher, ensuring dynamic field mappings do not include 'passthrough' types in index templates.

  • Who is affected by CVE-2024-37280?

    CVE-2024-37280 affects Elasticsearch versions between 8.13.1 and 8.14.0.

  • What is the risk of using affected versions for CVE-2024-37280?

    Using affected versions of Elasticsearch may lead to application crashes or denial of service due to the StackOverflow exceptions.

  • What actions should organizations take regarding CVE-2024-37280?

    Organizations should assess their current Elasticsearch versions and prioritize updating to the fixed version to prevent exploitation of CVE-2024-37280.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2025 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203