StackRadar

CVE-2024-52980

Medium

Advisory

Published 8 Apr 2025In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
6.5
base score, highest
EPSS
0.005
44th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
15
of 17,781 indexed, latest versions
Container images
16
deployed by those charts
Fix available
3 of 3
affected packages

Elasticsearch Uncontrolled Resource Consumption vulnerability

Carried by container images the latest versions of 15 of 17,781 indexed charts deploy, on 16 images.

Affected packageAffected versionsFixed inImages
elasticsearchmaven7.17.0, 7.17.1, 7.17.2, 7.17.3+11 more8.15.116
elasticsearchbitnami8.12.1-0, 8.12.2-08.15.12
Elasticsearchbitnami8.12.1-0, 8.12.2-08.15.12
OSV records
BIT-elasticsearch-2024-52980GHSA-ghfh-p92w-j4mg

Charts affected

15 by stars
ChartLatestAffected imagesRadar Score
sonarqubesonarqubeVerified publisher10.0.0+5211 of 3See more

sonarqube sonarqube 10.0.0+521

1 of the 3 container images this version deploys carry CVE-2024-52980.

Container imageDigestPackageFixed in
library/sonarqube:10.0.0-communityef9723cf4fe4
elasticsearch@8.6.1
8.15.1

Open the chart page →

6,556
seafiledatamateVerified publisher0.6.01 of 6See more

seafile datamate 0.6.0

1 of the 6 container images this version deploys carry CVE-2024-52980.

Container imageDigestPackageFixed in
bitnamilegacy/elasticsearch:8.12.1-debian-11-r29cfd2df1294d
elasticsearch@8.12.1-0
elasticsearch@8.12.1
Elasticsearch@8.12.1-0
8.15.1
8.15.1
8.15.1

Open the chart page →

27,267
repoflowrepoflow-helm-public0.9.11 of 8See more

repoflow repoflow-helm-public 0.9.1

1 of the 8 container images this version deploys carry CVE-2024-52980.

Container imageDigestPackageFixed in
library/elasticsearch:8.15.0310b9fc03b06
elasticsearch@8.15.0
8.15.1

Open the chart page →

13,521
data-fairdata354-helmVerified publisher1.1.21 of 12See more

data-fair data354-helm 1.1.2

1 of the 12 container images this version deploys carry CVE-2024-52980.

Container imageDigestPackageFixed in
ghcr.io/data-fair/elasticsearch:7.17.1aa45adaf59a7
elasticsearch@7.17.1
8.15.1

Open the chart page →

38,346
elasticinseefrlab2.2.01 of 2See more

elastic inseefrlab 2.2.0

1 of the 2 container images this version deploys carry CVE-2024-52980.

Container imageDigestPackageFixed in
library/elasticsearch:7.17.35e6ac15bf6a5
elasticsearch@7.17.3
8.15.1

Open the chart page →

17,284
clowder2ncsaVerified publisher1.9.71 of 12See more

clowder2 ncsa 1.9.7

1 of the 12 container images this version deploys carry CVE-2024-52980.

Container imageDigestPackageFixed in
bitnamilegacy/elasticsearch:8.12.215d4647fd491
elasticsearch@8.12.2-0
elasticsearch@8.12.2
Elasticsearch@8.12.2-0
8.15.1
8.15.1
8.15.1

Open the chart page →

37,373
portraitportraitVerified publisher0.2.132 of 8See more

portrait portrait 0.2.13

2 of the 8 container images this version deploys carry CVE-2024-52980.

Container imageDigestPackageFixed in
library/elasticsearch:7.17.0332c6d416808
elasticsearch@7.17.0
8.15.1
treskon/portrait:DEV-latest88e813f22347
elasticsearch@7.17.25
8.15.1

Open the chart page →

31,844
elasticsearchromanow-helm-chartsVerified publisher1.7.11 of 2See more

elasticsearch romanow-helm-charts 1.7.1

1 of the 2 container images this version deploys carry CVE-2024-52980.

Container imageDigestPackageFixed in
library/elasticsearch:7.17.8fdc73b3249c1
elasticsearch@7.17.8
8.15.1

Open the chart page →

6,045
airbyte-api-serverairbyteVerified publisher0.293.41 of 1See more

airbyte-api-server airbyte 0.293.4

1 of the 1 container images this version deploys carry CVE-2024-52980.

Container imageDigestPackageFixed in
airbyte/airbyte-api-server:0.63.8e1c5e7cfec8a
elasticsearch@7.17.21
8.15.1

Open the chart page →

854
elasticsearch-umbrellaempathyco0.8.121 of 3See more

elasticsearch-umbrella empathyco 0.8.12

1 of the 3 container images this version deploys carry CVE-2024-52980.

Container imageDigestPackageFixed in
empathyco/elasticsearch:7.17.2-memlock03e724e41eeb
elasticsearch@7.17.2
8.15.1

Open the chart page →

10,564
geonetwork-k8sgeonetwork-k8sVerified publisher4.2.82 of 5See more

geonetwork-k8s geonetwork-k8s 4.2.8

2 of the 5 container images this version deploys carry CVE-2024-52980.

Container imageDigestPackageFixed in
jingking/geonetwork-hnap:4.2.843e74ab234e1
elasticsearch@7.17.15
8.15.1
library/elasticsearch:7.17.1588c2ec10c7f2
elasticsearch@7.17.15
8.15.1

Open the chart page →

34,754
elasticsearch-chartmy-elasticsearch0.1.01 of 2See more

elasticsearch-chart my-elasticsearch 0.1.0

1 of the 2 container images this version deploys carry CVE-2024-52980.

Container imageDigestPackageFixed in
library/elasticsearch:7.17.35e6ac15bf6a5
elasticsearch@7.17.3
8.15.1

Open the chart page →

9,300
rada-platformrada-platform0.1.01 of 7See more

rada-platform rada-platform 0.1.0

1 of the 7 container images this version deploys carry CVE-2024-52980.

Container imageDigestPackageFixed in
trinodb/trino:45038c6f24ab1a4
elasticsearch@7.17.22
8.15.1

Open the chart page →

21,211
sonarquberedhat-cop0.1.131 of 1See more

sonarqube redhat-cop 0.1.13

1 of the 1 container images this version deploys carry CVE-2024-52980.

Container imageDigestPackageFixed in
library/sonarqube:10.7.0-community0842dcd4c8f8
elasticsearch@8.14.1
8.15.1

Open the chart page →

4,203
netforge-besvtechVerified publisher0.0.21 of 3See more

netforge-be svtech 0.0.2

1 of the 3 container images this version deploys carry CVE-2024-52980.

Container imageDigestPackageFixed in
conductoross/conductor:3.31.09fba127693e6
elasticsearch@7.17.11
8.15.1

Open the chart page →

4,674

Container images carrying it

16 by charts deploying them

A fixed version is listed for 3 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
library/elasticsearch:7.17.35e6ac15bf6a5
elasticsearch@7.17.3
8.15.1
2
airbyte/airbyte-api-server:0.63.8e1c5e7cfec8a
elasticsearch@7.17.21
8.15.1
1
bitnamilegacy/elasticsearch:8.12.215d4647fd491
elasticsearch@8.12.2-0
elasticsearch@8.12.2
Elasticsearch@8.12.2-0
8.15.1
8.15.1
8.15.1
1
bitnamilegacy/elasticsearch:8.12.1-debian-11-r29cfd2df1294d
elasticsearch@8.12.1-0
elasticsearch@8.12.1
Elasticsearch@8.12.1-0
8.15.1
8.15.1
8.15.1
1
conductoross/conductor:3.31.09fba127693e6
elasticsearch@7.17.11
8.15.1
1
empathyco/elasticsearch:7.17.2-memlock03e724e41eeb
elasticsearch@7.17.2
8.15.1
1
jingking/geonetwork-hnap:4.2.843e74ab234e1
elasticsearch@7.17.15
8.15.1
1
library/elasticsearch:8.15.0310b9fc03b06
elasticsearch@8.15.0
8.15.1
1
library/elasticsearch:7.17.0332c6d416808
elasticsearch@7.17.0
8.15.1
1
library/elasticsearch:7.17.1588c2ec10c7f2
elasticsearch@7.17.15
8.15.1
1
library/elasticsearch:7.17.8fdc73b3249c1
elasticsearch@7.17.8
8.15.1
1
library/sonarqube:10.7.0-community0842dcd4c8f8
elasticsearch@8.14.1
8.15.1
1
library/sonarqube:10.0.0-communityef9723cf4fe4
elasticsearch@8.6.1
8.15.1
1
treskon/portrait:DEV-latest88e813f22347
elasticsearch@7.17.25
8.15.1
1
trinodb/trino:45038c6f24ab1a4
elasticsearch@7.17.22
8.15.1
1
ghcr.io/data-fair/elasticsearch:7.17.1aa45adaf59a7
elasticsearch@7.17.1
8.15.1
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.