SB2024112084 - Allocation of Resources Without Limits or Throttling in Opencast
Published: November 20, 2024 Updated: April 23, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Allocation of Resources Without Limits or Throttling (CVE-ID: CVE-2024-52797)
The vulnerability allows a remote user to cause a denial of service.
The vulnerability exists due to allocation of resources without limits or throttling in Opencast's Elasticsearch integration when processing search queries. A remote user can send a search query that generates a syntactically invalid Elasticsearch query to cause a denial of service.
The issue can trigger repeated immediate retries in an infinite loop, causing excessive log growth that may exhaust disk space. By default, the affected endpoints require ROLE_ADMIN or ROLE_API_SERIES_VIEW.
Remediation
Install update from vendor's website.