DirectorySecurity Advisories
Sign In
Security Advisories

CGA-jgf5-4w5m-6h5j

Published

Last updated

https://images.chainguard.dev/security/CGA-jgf5-4w5m-6h5j
Package

elasticsearch-8

Latest Update
Fixed
Fixed Version

8.14.1-r0

Aliases
  • CVE-2024-37280
  • GHSA-4q22-422g-m4pj

Severity

4.9

Medium

CVSS V3

Summary

Elasticsearch StackOverflow vulnerability

Description

A flaw was discovered in Elasticsearch, affecting document ingestion when an index template contains a dynamic field mapping of “passthrough” type. Under certain circumstances, ingesting documents in this index would cause a StackOverflow exception to be thrown and ultimately lead to a Denial of Service. Note that passthrough fields is an experimental feature.

References

Updates


Safe Source for Open Source™
Media KitContact Us
© 2024 Chainguard. All Rights Reserved.
Private PolicyTerms of Use

Product

Chainguard Images