CVE-2024-43709

CVSS 3.1 Score 6.5 of 10 (medium)

Details

Published Jan 21, 2025
CWE ID 770

Summary

CVE-2024-43709 is a newly disclosed cybersecurity vulnerability affecting Elasticsearch. This issue arises due to an inadequate resource management mechanism that allows for excessive allocation without limitations or throttling. An attacker can exploit this flaw by designing a malicious SQL query, resulting in an OutOfMemoryError exception and a subsequent crash of the Elasticsearch system. This vulnerability poses a potential risk to organizations that run Elasticsearch, as it can lead to denial-of-service attacks and unplanned downtime.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share