CVE-2024-52980

CVSS 3.1 Score 6.5 of 10 (medium)

Details

Published Apr 8, 2025
CWE ID 400

Summary

CVE-2024-52980: A vulnerability was discovered in Elasticsearch, allowing a malicious user with read_pipeline privileges to cause a node crash through a large recursion using the innerForbidCircularReferences function in the PatternBank class. This issue can lead to denial-of-service conditions and potentially disrupt Elasticsearch cluster operations. It is recommended that affected organizations update their Elasticsearch instances to the latest patched version to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share