First published: Tue Apr 08 2025(Updated: )
An issue was discovered in Elasticsearch, where a large recursion using the Well-KnownText formatted string with nested GeometryCollection objects could cause a stackoverflow.
Credit: bressers@elastic.co
Affected Software | Affected Version | How to fix |
---|---|---|
Elastic | ||
maven/org.elasticsearch:elasticsearch | >=8.0.0-alpha1<=8.15.0 | 8.15.1 |
maven/org.elasticsearch:elasticsearch | >=7.17.0<=7.17.23 | 7.17.24 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-52981 is classified as a high severity vulnerability due to its potential to cause a stack overflow.
To remediate CVE-2024-52981, update Elasticsearch to the patched versions provided in the security update.
CVE-2024-52981 affects certain versions of Elasticsearch which utilize Well-KnownText formatted strings with nested GeometryCollection objects.
CVE-2024-52981 can be exploited to crash the Elasticsearch service by triggering a stack overflow.
Currently, there is no documented workaround for CVE-2024-52981; the best course of action is to apply the latest updates.