VYPR
Moderate severityNVD Advisory· Published Jan 21, 2025· Updated Feb 21, 2025

Elasticsearch allocation of resources without limits or throttling leads to crash

CVE-2024-43709

Description

An allocation of resources without limits or throttling in Elasticsearch can lead to an OutOfMemoryError exception resulting in a crash via a specially crafted query using an SQL function.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
org.elasticsearch:elasticsearchMaven
< 7.17.217.17.21
org.elasticsearch:elasticsearchMaven
>= 8.0.0, < 8.13.38.13.3

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

4

News mentions

0

No linked articles in our index yet.