DirectorySecurity Advisories
Sign In
Security Advisories

CVE-2024-37280

Published

Last updated

NVD

https://nvd.nist.gov/vuln/detail/CVE-2024-37280

CGA ID

CGA-683m-fm7m-7mvf

Severity

4.9

Medium

CVSS V3

Summary

Elasticsearch StackOverflow vulnerability

Description

A flaw was discovered in Elasticsearch, affecting document ingestion when an index template contains a dynamic field mapping of “passthrough” type. Under certain circumstances, ingesting documents in this index would cause a StackOverflow exception to be thrown and ultimately lead to a Denial of Service. Note that passthrough fields is an experimental feature.

References

  • https://images.chainguard.dev/security/CGA-683m-fm7m-7mvf

Affected packages


Safe Source for Open Source™
Media KitContact Us
© 2024 Chainguard. All Rights Reserved.
Private PolicyTerms of Use

Product

Chainguard Images