PT-2014-5099 · Elastic · Elasticsearch
Published
2014-07-28
·
Updated
2026-01-03
·
CVE-2014-3120
CVSS v3.1
8.1
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Elasticsearch versions prior to 1.2
Description
The default configuration in Elasticsearch enables dynamic scripting, which allows remote attackers to execute arbitrary MVEL expressions and Java code via the
source parameter to the search endpoint. This issue only violates the vendor's intended security policy if the user does not run Elasticsearch in its own independent virtual machine.Recommendations
For versions prior to 1.2, consider disabling dynamic scripting to prevent the execution of arbitrary MVEL expressions and Java code. As a temporary workaround, restrict access to the
search endpoint to minimize the risk of exploitation.Exploit
Fix
RCE
Improper Access Control
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Elasticsearch