First published: Thu May 01 2025(Updated: )
Uncontrolled Resource Consumption in Elasticsearch while evaluating specifically crafted search templates with Mustache functions can lead to Denial of Service by causing the Elasticsearch node to crash.
Credit: bressers@elastic.co
Affected Software | Affected Version | How to fix |
---|---|---|
Elastic |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-52979 is rated as a high-severity vulnerability due to its potential to cause denial of service by crashing Elasticsearch nodes.
To fix CVE-2024-52979, update your Elasticsearch to the latest version provided by Elastic that addresses this vulnerability.
CVE-2024-52979 is caused by uncontrolled resource consumption while evaluating crafted search templates that use Mustache functions.
CVE-2024-52979 affects multiple versions of Elasticsearch, specifically those that process search templates without adequate resource controls.
CVE-2024-52979 can lead to denial of service, resulting in crashes that may disrupt your Elasticsearch deployment and affect availability.