CVE-2024-52979

MEDIUM

Elasticsearch < 7.17.25 - Denial of Service via Mustache Function in Search Templates

Title source: llm
STIX 2.1

Description

Uncontrolled Resource Consumption in Elasticsearch while evaluating specifically crafted search templates with Mustache functions can lead to Denial of Service by causing the Elasticsearch node to crash.

Scores

CVSS v3 6.5
EPSS 0.0020
EPSS Percentile 41.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-400
Status published
Products (2)
elastic/elasticsearch < 7.17.25
org.elasticsearch/elasticsearch 0 - 7.17.25Maven
Published May 01, 2025
Tracked Since Feb 18, 2026