Elasticsearch Potential Node Crash due to Large Recursion in `innerForbidCircularReferences` Function
Moderate severity
GitHub Reviewed
Published
Apr 8, 2025
to the GitHub Advisory Database
•
Updated Apr 9, 2025
Package
Affected versions
>= 7.17.0, < 8.15.1
Patched versions
8.15.1
Description
Published by the National Vulnerability Database
Apr 8, 2025
Published to the GitHub Advisory Database
Apr 8, 2025
Last updated
Apr 9, 2025
Reviewed
Apr 9, 2025
A flaw was discovered in Elasticsearch, where a large recursion using the innerForbidCircularReferences function of the PatternBank class could cause the Elasticsearch node to crash.
A successful attack requires a malicious user to have read_pipeline Elasticsearch cluster privilege assigned to them.
References