Medium severity6.5NVD Advisory· Published Apr 8, 2025· Updated Jun 17, 2026
CVE-2024-52980
CVE-2024-52980
Description
A flaw was discovered in Elasticsearch, where a large recursion using the innerForbidCircularReferences function of the PatternBank class could cause the Elasticsearch node to crash.
A successful attack requires a malicious user to have read_pipeline Elasticsearch cluster privilege assigned to them.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
8cpe:2.3:a:elastic:elasticsearch:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:elastic:elasticsearch:*:*:*:*:*:*:*:*range: >=7.17.0,<8.15.1
- (no CPE)range: 7.17.0
- osv-coords6 versionspkg:apk/chainguard/conductor-fipspkg:apk/chainguard/elasticsearch-7pkg:apk/chainguard/elasticsearch-7-iamguardedpkg:bitnami/elasticsearchpkg:maven/org.elasticsearch/elasticsearchpkg:apk/chainguard/conductor
< 3.31.0-r4+ 5 more
- (no CPE)range: < 3.31.0-r4
- (no CPE)range: < 7.17.29-r11
- (no CPE)range: < 7.17.29-r11
- (no CPE)range: >= 7.17.0, < 8.15.1
- (no CPE)range: >= 7.17.0, < 8.15.1
- (no CPE)range: < 3.31.0-r4
Patches
Vulnerability mechanics
References
5- discuss.elastic.co/t/elasticsearch-8-15-1-security-update-esa-2024-34/376919nvdIssue TrackingPatchVendor Advisory
- github.com/advisories/GHSA-ghfh-p92w-j4mgghsaADVISORY
- github.com/elastic/elasticsearch/commit/4e5c6801f4d60f100f122072f6bf35b21fd722a5ghsa
- github.com/elastic/elasticsearch/commit/a02dc7165c75f12701f8d47a2bdefe5283735267ghsa
- nvd.nist.gov/vuln/detail/CVE-2024-52980ghsa
News mentions
0No linked articles in our index yet.