CVE-2024-52981: High severity elastic vulnerability
An issue was discovered in Elasticsearch, where a large recursion using the Well-KnownText formatted string with nested GeometryCollection objects could cause a stackoverflow.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2024-52981?
CVE-2024-52981 is classified as a high severity vulnerability due to its potential to cause a stack overflow.
How do I fix CVE-2024-52981?
To remediate CVE-2024-52981, update Elasticsearch to the patched versions provided in the security update.
What versions of Elasticsearch are affected by CVE-2024-52981?
CVE-2024-52981 affects certain versions of Elasticsearch which utilize Well-KnownText formatted strings with nested GeometryCollection objects.
What kind of attack does CVE-2024-52981 facilitate?
CVE-2024-52981 can be exploited to crash the Elasticsearch service by triggering a stack overflow.
Is there a workaround for CVE-2024-52981?
Currently, there is no documented workaround for CVE-2024-52981; the best course of action is to apply the latest updates.