PT-2014-5099 · Elastic · Elasticsearch
CVE-2014-3120
·
Publicado
2014-07-28
·
Atualizado
2026-01-03
CVSS v3.1
8.1
Alta
| Vetor | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Elasticsearch versions prior to 1.2
Description
The default configuration in Elasticsearch enables dynamic scripting, which allows remote attackers to execute arbitrary MVEL expressions and Java code via the
source parameter to the search endpoint. This issue only violates the vendor's intended security policy if the user does not run Elasticsearch in its own independent virtual machine.Recommendations
For versions prior to 1.2, consider disabling dynamic scripting to prevent the execution of arbitrary MVEL expressions and Java code. As a temporary workaround, restrict access to the
search endpoint to minimize the risk of exploitation.Exploit
Correção
RCE
Improper Access Control
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Elasticsearch