Vulnerabilities > Elastic > Elasticsearch > 7.17.16

DATE CVE VULNERABILITY TITLE RISK
2025-01-21 CVE-2024-43709 Allocation of Resources Without Limits or Throttling vulnerability in Elastic Elasticsearch
An allocation of resources without limits or throttling in Elasticsearch can lead to an OutOfMemoryError exception resulting in a crash via a specially crafted query using an SQL function.
network
low complexity
elastic CWE-770
7.5
2024-07-31 CVE-2024-23444 Missing Encryption of Sensitive Data vulnerability in Elastic Elasticsearch
It was discovered by Elastic engineering that when elasticsearch-certutil CLI tool is used with the csr option in order to create a new Certificate Signing Requests, the associated private key that is generated is stored on disk unencrypted even if the --pass parameter is passed in the command invocation.
network
low complexity
elastic CWE-311
7.5
2024-03-27 CVE-2024-23450 Unspecified vulnerability in Elastic Elasticsearch
A flaw was discovered in Elasticsearch, where processing a document in a deeply nested pipeline on an ingest node could cause the Elasticsearch node to crash.
network
low complexity
elastic
7.5