Skip to content
ElasticsearchGHSA-jgx4-7v3v-vwfm

Elasticsearch allocation of resources without limits or throttling leads to crash

Medium6.5CVE-2024-43709 · Published Jan 21, 2025 · updated Feb 21, 2025

An allocation of resources without limits or throttling in Elasticsearch can lead to an OutOfMemoryError exception resulting in a crash via a specially crafted query using an SQL function.

GitHub advisory

Affected versions

PackageAffectedFixed in
org.elasticsearch:elasticsearch
Maven
< 7.17.217.17.21
>= 8.0.0, < 8.13.38.13.3
Details and references
CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Severity from
GitHub (reviewed advisory)
Weakness
CWE-770
Also known as
BIT-elasticsearch-2024-43709, CVE-2024-43709

More Elasticsearch advisories

All Elasticsearch
Advisory
Elasticsearch Uncontrolled Resource Consumption Vulnerability
Medium6.5May 1, 2025
Elasticsearch Vulnerable to Stack Overflow due to a Large Recursion
Medium4.9Apr 8, 2025
Elasticsearch Potential Node Crash due to Large Recursion in `innerForbidCircularReferences` Function
Medium6.5Apr 8, 2025
Elasticsearch Incorrect Authorization vulnerability
MediumDec 17, 2024
Elasticsearch stores private key on disk unencrypted
Medium4.9Jul 31, 2024
Elasticsearch Insertion of Sensitive Information into Log File
Medium5.2Jul 26, 2024

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.