CVE-2024-52979

Published May 1, 2025

Last updated 7 months ago

Overview

Description
Uncontrolled Resource Consumption in Elasticsearch while evaluating specifically crafted search templates with Mustache functions can lead to Denial of Service by causing the Elasticsearch node to crash.
Source
bressers@elastic.co
NVD status
Analyzed
Products
elasticsearch

Risk scores

CVSS 3.1

Type
Primary
Base score
7.5
Impact score
3.6
Exploitability score
3.9
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Severity
HIGH

Weaknesses

bressers@elastic.co
CWE-400

Social media

Hype score
Not currently trending

Configurations