An allocation of resources without limits or throttling in Elasticsearch can lead to an OutOfMemoryError exception resulting in a crash via a specially crafted query using an SQL function.
Advisories
Source ID Title
EUVD EUVD EUVD-2025-0176 An allocation of resources without limits or throttling in Elasticsearch can lead to an OutOfMemoryError exception resulting in a crash via a specially crafted query using an SQL function.
Github GHSA Github GHSA GHSA-jgx4-7v3v-vwfm Elasticsearch allocation of resources without limits or throttling leads to crash
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Fri, 21 Feb 2025 18:30:00 +0000

Type Values Removed Values Added
References

Fri, 31 Jan 2025 20:45:00 +0000

Type Values Removed Values Added
First Time appeared Elastic
Elastic elasticsearch
CPEs cpe:2.3:a:elastic:elasticsearch:*:*:*:*:*:*:*:*
Vendors & Products Elastic
Elastic elasticsearch

Wed, 22 Jan 2025 02:00:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Moderate


Tue, 21 Jan 2025 17:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 21 Jan 2025 11:15:00 +0000

Type Values Removed Values Added
Description An allocation of resources without limits or throttling in Elasticsearch can lead to an OutOfMemoryError exception resulting in a crash via a specially crafted query using an SQL function.
Title Elasticsearch allocation of resources without limits or throttling leads to crash
Weaknesses CWE-770
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: elastic

Published:

Updated: 2025-02-21T18:03:29.257Z

Reserved: 2024-08-15T09:26:41.511Z

Link: CVE-2024-43709

cve-icon Vulnrichment

Updated: 2025-02-21T18:03:29.257Z

cve-icon NVD

Status : Modified

Published: 2025-01-21T11:15:09.807

Modified: 2025-02-21T18:15:16.913

Link: CVE-2024-43709

cve-icon Redhat

Severity : Moderate

Publid Date: 2025-01-21T11:00:11Z

Links: CVE-2024-43709 - Bugzilla

cve-icon OpenCVE Enrichment

No data.