CVE-2024-23450

A flaw was discovered in Elasticsearch, where processing a document in a deeply nested pipeline on an ingest node could cause the Elasticsearch node to crash.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:elastic:elasticsearch:*:*:*:*:*:*:*:*
cpe:2.3:a:elastic:elasticsearch:*:*:*:*:*:*:*:*

History

04 Feb 2025, 14:23

Type Values Removed Values Added
References () https://discuss.elastic.co/t/elasticsearch-8-13-0-7-17-19-security-update-esa-2024-06/356314 - () https://discuss.elastic.co/t/elasticsearch-8-13-0-7-17-19-security-update-esa-2024-06/356314 - Vendor Advisory
References () https://security.netapp.com/advisory/ntap-20240517-0010/ - () https://security.netapp.com/advisory/ntap-20240517-0010/ - Third Party Advisory
References () https://www.elastic.co/community/security - () https://www.elastic.co/community/security - Vendor Advisory
CWE NVD-CWE-noinfo
First Time Elastic elasticsearch
Elastic
CPE cpe:2.3:a:elastic:elasticsearch:*:*:*:*:*:*:*:*

21 Nov 2024, 08:57

Type Values Removed Values Added
References () https://discuss.elastic.co/t/elasticsearch-8-13-0-7-17-19-security-update-esa-2024-06/356314 - () https://discuss.elastic.co/t/elasticsearch-8-13-0-7-17-19-security-update-esa-2024-06/356314 -
References () https://security.netapp.com/advisory/ntap-20240517-0010/ - () https://security.netapp.com/advisory/ntap-20240517-0010/ -
References () https://www.elastic.co/community/security - () https://www.elastic.co/community/security -

10 Jun 2024, 17:16

Type Values Removed Values Added
References
  • () https://security.netapp.com/advisory/ntap-20240517-0010/ -
Summary
  • (es) Se descubrió una falla en Elasticsearch, donde el procesamiento de un documento en una canalización profundamente anidada en un nodo de ingesta podría provocar que el nodo Elasticsearch fallara.

27 Mar 2024, 17:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-03-27 17:15

Updated : 2025-02-04 14:23


NVD link : CVE-2024-23450

Mitre link : CVE-2024-23450

CVE.ORG link : CVE-2024-23450


JSON object : View

Products Affected

elastic

  • elasticsearch
CWE
CWE-400

Uncontrolled Resource Consumption

NVD-CWE-noinfo