Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2024-43709


An allocation of resources without limits or throttling in Elasticsearch can lead to an OutOfMemoryError exception resulting in a crash via a specially crafted query using an SQL function.


Published

2025-01-21T11:15:09.807

Last Modified

2025-02-21T18:15:16.913

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 6.5 (MEDIUM)

Weaknesses
  • Type: Secondary
    CWE-770
  • Type: Primary
    CWE-770

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application elastic elasticsearch < 7.17.21 Yes
Application elastic elasticsearch < 8.13.3 Yes

References