ElasticsearchGHSA-jgx4-7v3v-vwfm
Elasticsearch allocation of resources without limits or throttling leads to crash
Medium6.5CVE-2024-43709 · Published Jan 21, 2025 · updated Feb 21, 2025
An allocation of resources without limits or throttling in Elasticsearch can lead to an OutOfMemoryError exception resulting in a crash via a specially crafted query using an SQL function.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| org.elasticsearch:elasticsearch Maven | < 7.17.21 | 7.17.21 |
| >= 8.0.0, < 8.13.3 | 8.13.3 |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-770
- Also known as
- BIT-elasticsearch-2024-43709, CVE-2024-43709
More Elasticsearch advisories
All Elasticsearch| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| May 12025 | Elasticsearch Uncontrolled Resource Consumption Vulnerability | Medium6.5 | 7.17.25+1 more |
| Apr 82025 | Elasticsearch Vulnerable to Stack Overflow due to a Large Recursion | Medium4.9 | 7.17.24+1 more |
| Apr 82025 | Elasticsearch Potential Node Crash due to Large Recursion in `innerForbidCircularReferences` Function | Medium6.5 | 8.15.1 |
| Dec 172024 | Elasticsearch Incorrect Authorization vulnerability | Medium | 8.16.2 |
| Jul 312024 | Elasticsearch stores private key on disk unencrypted | Medium4.9 | 7.17.23+1 more |
| Jul 262024 | Elasticsearch Insertion of Sensitive Information into Log File | Medium5.2 | 7.17.16+1 more |