CVE-2024-37280 — Heap-based Buffer Overflow in Elasticsearch
Severity
4.9MEDIUMNVD
EPSS
0.3%
top 43.55%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJun 13
Description
A flaw was discovered in Elasticsearch, affecting document ingestion when an index template contains a dynamic field mapping of “passthrough” type. Under certain circumstances, ingesting documents in this index would cause a StackOverflow exception to be thrown and ultimately lead to a Denial of Service. Note that passthrough fields is an experimental feature.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:HExploitability: 1.2 | Impact: 3.6
Affected Packages2 packages
🔴Vulnerability Details
4OSV▶
CVE-2024-37280: A flaw was discovered in Elasticsearch, affecting document ingestion when an index template contains a dynamic field mapping of “passthrough” type↗2024-06-13
📋Vendor Advisories
1Red Hat
▶