CVE-2024-43709

An allocation of resources without limits or throttling in Elasticsearch can lead to an OutOfMemoryError exception resulting in a crash via a specially crafted query using an SQL function.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:elastic:elasticsearch:*:*:*:*:*:*:*:*
cpe:2.3:a:elastic:elasticsearch:*:*:*:*:*:*:*:*

History

21 Feb 2025, 18:15

Type Values Removed Values Added
References
  • () https://security.netapp.com/advisory/ntap-20250221-0007/ -

31 Jan 2025, 20:20

Type Values Removed Values Added
First Time Elastic elasticsearch
Elastic
CPE cpe:2.3:a:elastic:elasticsearch:*:*:*:*:*:*:*:*
References () https://discuss.elastic.co/t/elasticsearch-7-17-21-and-8-13-3-security-update-esa-2024-25/373442 - () https://discuss.elastic.co/t/elasticsearch-7-17-21-and-8-13-3-security-update-esa-2024-25/373442 - Vendor Advisory
Summary
  • (es) Una asignación de recursos sin límites ni limitación en Elasticsearch puede generar una excepción OutOfMemoryError que resulte en un bloqueo a través de una consulta especialmente manipulada que utiliza una función SQL.

21 Jan 2025, 11:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-01-21 11:15

Updated : 2025-02-21 18:15


NVD link : CVE-2024-43709

Mitre link : CVE-2024-43709

CVE.ORG link : CVE-2024-43709


JSON object : View

Products Affected

elastic

  • elasticsearch
CWE
CWE-770

Allocation of Resources Without Limits or Throttling