CVE-2014-3120
CVSS 2.0 Score 6.8 of 10 (medium)
Details
Published Jul 28, 2014
Updated: Jan 6, 2025
CWE ID 284
Summary
CVE-2014-3120 is a vulnerability affecting Elasticsearch versions prior to 1.2. The issue lies in the default configuration that enables dynamic scripting, making it possible for remote attackers to execute arbitrary MVEL expressions and Java code through the source parameter in _search queries. This bypasses the intended security policy, but only poses a significant risk if Elasticsearch is not operated in an isolated virtual machine.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Elasticsearch
Affected Vendors
- Elastic