Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2024-37280

Опубликовано: 13 июн. 2024
Источник: nvd
CVSS3: 4.9
EPSS Низкий

Описание

A flaw was discovered in Elasticsearch, affecting document ingestion when an index template contains a dynamic field mapping of “passthrough” type. Under certain circumstances, ingesting documents in this index would cause a StackOverflow exception to be thrown and ultimately lead to a Denial of Service. Note that passthrough fields is an experimental feature.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:elastic:elasticsearch:*:*:*:*:*:*:*:*
Версия от 8.13.1 (включая) до 8.14.0 (исключая)

EPSS

Процентиль: 56%
0.00335
Низкий

4.9 Medium

CVSS3

Дефекты

CWE-122
CWE-787

Связанные уязвимости

CVSS3: 4.9
ubuntu
больше 1 года назад

A flaw was discovered in Elasticsearch, affecting document ingestion when an index template contains a dynamic field mapping of “passthrough” type. Under certain circumstances, ingesting documents in this index would cause a StackOverflow exception to be thrown and ultimately lead to a Denial of Service. Note that passthrough fields is an experimental feature.

CVSS3: 4.9
redhat
больше 1 года назад

A flaw was discovered in Elasticsearch, affecting document ingestion when an index template contains a dynamic field mapping of “passthrough” type. Under certain circumstances, ingesting documents in this index would cause a StackOverflow exception to be thrown and ultimately lead to a Denial of Service. Note that passthrough fields is an experimental feature.

CVSS3: 4.9
debian
больше 1 года назад

A flaw was discovered in Elasticsearch, affecting document ingestion w ...

CVSS3: 4.9
github
больше 1 года назад

Elasticsearch StackOverflow vulnerability

EPSS

Процентиль: 56%
0.00335
Низкий

4.9 Medium

CVSS3

Дефекты

CWE-122
CWE-787