First published: Tue Apr 08 2025(Updated: )
A flaw was discovered in Elasticsearch, where a large recursion using the innerForbidCircularReferences function of the PatternBank class could cause the Elasticsearch node to crash. A successful attack requires a malicious user to have read_pipeline Elasticsearch cluster privilege assigned to them.
Credit: bressers@elastic.co
Affected Software | Affected Version | How to fix |
---|---|---|
Elastic | ||
maven/org.elasticsearch:elasticsearch | >=7.17.0<8.15.1 | 8.15.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2024-52980 is critical due to its potential to crash Elasticsearch nodes.
Fix CVE-2024-52980 by updating to the latest version of Elasticsearch where the vulnerability is patched.
CVE-2024-52980 affects users of Elasticsearch with read_pipeline cluster privilege.
CVE-2024-52980 can be exploited through a large recursion in the innerForbidCircularReferences function.
CVE-2024-52980 can lead to crashes of Elasticsearch nodes if exploited successfully.