Recursion Flaw in Elasticsearch Affects Data Stability
CVE-2024-52980
6.5MEDIUM
What is CVE-2024-52980?
A significant vulnerability exists in Elasticsearch, where an excessive recursion issue in the innerForbidCircularReferences function of the PatternBank class can lead to crashes of the Elasticsearch node. To exploit this vulnerability, an attacker must possess the read_pipeline cluster privilege, which allows them to manipulate the system and potentially disrupt data stability.
Affected Version(s)
Elasticsearch 7.17.0 <= 8.15.0