Recursion Flaw in Elasticsearch Affects Data Stability
CVE-2024-52980

6.5MEDIUM

Key Information:

Vendor
Elastic
Status
Vendor
CVE Published:
8 April 2025

Summary

A significant vulnerability exists in Elasticsearch, where an excessive recursion issue in the innerForbidCircularReferences function of the PatternBank class can lead to crashes of the Elasticsearch node. To exploit this vulnerability, an attacker must possess the read_pipeline cluster privilege, which allows them to manipulate the system and potentially disrupt data stability.

Affected Version(s)

Elasticsearch 7.17.0 <= 8.15.0

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.