CVE-2024-37280Heap-based Buffer Overflow in Elasticsearch

Severity
4.9MEDIUMNVD
EPSS
0.3%
top 43.55%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJun 13

Description

A flaw was discovered in Elasticsearch, affecting document ingestion when an index template contains a dynamic field mapping of “passthrough” type. Under certain circumstances, ingesting documents in this index would cause a StackOverflow exception to be thrown and ultimately lead to a Denial of Service. Note that passthrough fields is an experimental feature.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:HExploitability: 1.2 | Impact: 3.6

Affected Packages2 packages

NVDelastic/elasticsearch8.13.18.14.0
CVEListV5elastic/elasticsearch8.13.18.13.4

🔴Vulnerability Details

4
GHSA
Elasticsearch StackOverflow vulnerability2024-06-13
OSV
Elasticsearch StackOverflow vulnerability2024-06-13
CVEList
Elasticsearch StackOverflow vulnerability2024-06-13
OSV
CVE-2024-37280: A flaw was discovered in Elasticsearch, affecting document ingestion when an index template contains a dynamic field mapping of “passthrough” type2024-06-13

📋Vendor Advisories

1
Red Hat
elasticsearch: Ingesting documents in this index would cause a StackOverflow exception2024-06-07
CVE-2024-37280 — Heap-based Buffer Overflow in Elastic | cvebase