PT-2025-15467 · Elastic · Elasticsearch

Published

2025-04-08

·

Updated

2025-04-21

·

CVE-2024-52980

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions: Elasticsearch (affected versions not specified)
Description: A flaw was discovered in Elasticsearch, where a large recursion using the innerForbidCircularReferences function of the PatternBank class could cause the Elasticsearch node to crash. A successful attack requires a malicious user to have read pipeline Elasticsearch cluster privilege assigned to them.
Recommendations: At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Resource Exhaustion

Weakness Enumeration

Related Identifiers

BIT-ELASTICSEARCH-2024-52980
CVE-2024-52980
ECHO-912E-995E-04AC
GHSA-GHFH-P92W-J4MG

Affected Products

Elasticsearch