CVE-2024-52980

Publication date

2025-04-08 16:43:41

Family

elastic

State

PUBLISHED

Description

A flaw was discovered in Elasticsearch, where a large recursion using the innerForbidCircularReferences function of the PatternBank class could cause the Elasticsearch node to crash. A successful attack requires a malicious user to have read_pipeline Elasticsearch cluster privilege assigned to them.