← Back

CVE-2024-52979

nvd nist
Published: May 1, 2025Modified: Oct 2, 2025

JSON object

Loading...
7.5
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Exploitability: 3.9 / Impact: 3.6
Source: NVD

Description

Uncontrolled Resource Consumption in Elasticsearch while evaluating specifically crafted search templates with Mustache functions can lead to Denial of Service by causing the Elasticsearch node to crash.

Affected (2)

1 product
Elasticsearch
Configuration A
2 vulnerable
Vulnerable SoftwareAffected Versions
Elastic
Before 7.17.25
From 8.0.0 to 8.16.0

Timeline

No history available yet.