Moderate severityNVD Advisory· Published Jan 21, 2025· Updated Feb 21, 2025
Elasticsearch allocation of resources without limits or throttling leads to crash
CVE-2024-43709
Description
An allocation of resources without limits or throttling in Elasticsearch can lead to an OutOfMemoryError exception resulting in a crash via a specially crafted query using an SQL function.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
org.elasticsearch:elasticsearchMaven | < 7.17.21 | 7.17.21 |
org.elasticsearch:elasticsearchMaven | >= 8.0.0, < 8.13.3 | 8.13.3 |
Affected products
1- Range: 7.17.0, 8.0.0
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
4News mentions
0No linked articles in our index yet.