Recursion Flaw in Elasticsearch Affects Data Stability
CVE-2024-52980
6.5MEDIUM
Summary
A significant vulnerability exists in Elasticsearch, where an excessive recursion issue in the innerForbidCircularReferences function of the PatternBank class can lead to crashes of the Elasticsearch node. To exploit this vulnerability, an attacker must possess the read_pipeline cluster privilege, which allows them to manipulate the system and potentially disrupt data stability.
Affected Version(s)
Elasticsearch 7.17.0 <= 8.15.0
References
CVSS V3.1
Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved