CVE-2024-37280

A flaw was discovered in Elasticsearch, affecting document ingestion when an index template contains a dynamic field mapping of “passthrough” type. Under certain circumstances, ingesting documents in this index would cause a StackOverflow exception to be thrown and ultimately lead to a Denial of Service. Note that passthrough fields is an experimental feature.
Configurations

Configuration 1 (hide)

cpe:2.3:a:elastic:elasticsearch:*:*:*:*:*:*:*:*

History

03 Oct 2024, 19:37

Type Values Removed Values Added
References () https://discuss.elastic.co/t/elasticsearch-8-14-0-security-update-esa-2024-14/361007 - () https://discuss.elastic.co/t/elasticsearch-8-14-0-security-update-esa-2024-14/361007 - Vendor Advisory
CPE cpe:2.3:a:elastic:elasticsearch:*:*:*:*:*:*:*:*
CWE CWE-787
First Time Elastic
Elastic elasticsearch
Summary
  • (es) Se descubrió una falla en Elasticsearch que afecta la ingesta de documentos cuando una plantilla de índice contiene un mapeo de campo dinámico de tipo "paso a través". En determinadas circunstancias, la ingesta de documentos en este índice provocaría que se lanzara una excepción de StackOverflow y, en última instancia, provocaría una denegación de servicio. Tenga en cuenta que los campos de transferencia son una característica experimental.

13 Jun 2024, 17:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-06-13 17:15

Updated : 2024-10-03 19:37


NVD link : CVE-2024-37280

Mitre link : CVE-2024-37280

CVE.ORG link : CVE-2024-37280


JSON object : View

Products Affected

elastic

  • elasticsearch
CWE
CWE-787

Out-of-bounds Write

CWE-122

Heap-based Buffer Overflow