# Elasticsearch 8.15.1 Security Update (ESA-2024-34)

**URL:** <https://discuss.elastic.co/t/elasticsearch-8-15-1-security-update-esa-2024-34/376919>\
**Category:** Security Announcements\
**Created:** [April 8, 2025, 3:54pm UTC](https://discuss.elastic.co/t/elasticsearch-8-15-1-security-update-esa-2024-34/376919 "2025-04-08T15:54:09Z")\
**Posts on this page:** 1\
**Page:** 1

<div class="post-metadata">

**Author:** ![Bryan\_Garcia](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bryan_garcia/32/148179_2.png) [@Bryan\_Garcia](https://discuss.elastic.co/u/Bryan_Garcia)\
**Post date:** [April 8, 2025, 3:54pm UTC](https://discuss.elastic.co/t/elasticsearch-8-15-1-security-update-esa-2024-34/376919/1 "2025-04-08T15:54:09Z")

</div>

**Elasticsearch Uncontrolled Resource Consumption vulnerability (ESA-2024-34)**

A flaw was discovered in Elasticsearch, where a large recursion using the innerForbidCircularReferences function of the PatternBank class could cause the Elasticsearch node to crash.

A successful attack requires a malicious user to have read\_pipeline Elasticsearch cluster privilege assigned to them.

**Affected Versions:**

Elasticsearch versions 7.17.0 to 8.15.0.

**Solutions and Mitigations:**

Users should upgrade to version 8.15.1 or higher.

**For Users That Cannot Upgrade:**

Remove the Elasticsearch cluster privileges outlined above from users.

**Severity:** CVSS v3.1: 6.5 (Medium) - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

**CVE ID:** CVE-2024-52980
