Medium severity6.5NVD Advisory· Published Jan 21, 2025· Updated Jun 17, 2026
CVE-2024-43709
CVE-2024-43709
Description
An allocation of resources without limits or throttling in Elasticsearch can lead to an OutOfMemoryError exception resulting in a crash via a specially crafted query using an SQL function.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
org.elasticsearch:elasticsearchMaven | < 7.17.21 | 7.17.21 |
org.elasticsearch:elasticsearchMaven | >= 8.0.0, < 8.13.3 | 8.13.3 |
Affected products
4cpe:2.3:a:elastic:elasticsearch:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:elastic:elasticsearch:*:*:*:*:*:*:*:*range: >=7.17.0,<7.17.21
- (no CPE)range: 7.17.0, 8.0.0
- osv-coords2 versions
>= 7.17.0, < 7.17.21+ 1 more
- (no CPE)range: >= 7.17.0, < 7.17.21
- (no CPE)range: < 7.17.21
Patches
Vulnerability mechanics
References
5- discuss.elastic.co/t/elasticsearch-7-17-21-and-8-13-3-security-update-esa-2024-25/373442nvdVendor AdvisoryWEB
- github.com/advisories/GHSA-jgx4-7v3v-vwfmghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2024-43709ghsaADVISORY
- security.netapp.com/advisory/ntap-20250221-0007ghsaWEB
- security.netapp.com/advisory/ntap-20250221-0007/nvd
News mentions
0No linked articles in our index yet.