#VU127020 Allocation of Resources Without Limits or Throttling in Opencast - CVE-2024-52797
Published: November 20, 2024 / Updated: April 23, 2026
Opencast
Apereo Foundation
Description
The vulnerability allows a remote user to cause a denial of service.
The vulnerability exists due to allocation of resources without limits or throttling in Opencast's Elasticsearch integration when processing search queries. A remote user can send a search query that generates a syntactically invalid Elasticsearch query to cause a denial of service.
The issue can trigger repeated immediate retries in an infinite loop, causing excessive log growth that may exhaust disk space. By default, the affected endpoints require ROLE_ADMIN or ROLE_API_SERIES_VIEW.