CVE-2014-3120

CVSS 2.0 Score 6.8 of 10 (medium)

Details

Published Jul 28, 2014
Updated: Jan 6, 2025
CWE ID 284

Summary

CVE-2014-3120 is a vulnerability affecting Elasticsearch versions prior to 1.2. The issue lies in the default configuration that enables dynamic scripting, making it possible for remote attackers to execute arbitrary MVEL expressions and Java code through the source parameter in _search queries. This bypasses the intended security policy, but only poses a significant risk if Elasticsearch is not operated in an isolated virtual machine.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share