Resource exhaustion in Elasticsearch - CVE-2024-52980

 

Resource exhaustion in Elasticsearch - CVE-2024-52980

Published: April 8, 2025


Vulnerability identifier: #VU107229
CSH Severity: Medium
CVSS v4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-52980
CWE-ID: CWE-400
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to perform a denial of service (DoS) attack.

The vulnerability exists due to application does not properly control consumption of internal resources. A remote user can use the innerForbidCircularReferences function of the PatternBank class to cause the Elasticsearch node to crash.


Affected software

Elasticsearch
watsonx.data
IBM Cloud Pak for Watson AIOps
IBM Watson Discovery for IBM Cloud Pak for Data

How to mitigate CVE-2024-52980

Install updates from vendor's website.

Elasticsearch - update to 8.15.1
watsonx.data - update to 2.2.2
IBM Cloud Pak for Watson AIOps - update to 4.10.0
IBM Watson Discovery for IBM Cloud Pak for Data - update to 5.3.2

External References

Related Security Bulletins