Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2014-3120

The default configuration in Elasticsearch before 1.2 enables dynamic scripting, which allows remote attackers to execute arbitrary MVEL expressions and Java code via the source parameter to _search. NOTE: this only violates the vendor's intended security policy if the user does not run Elasticsearch in its own independent virtual machine.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.798
EPSS Ranking 99.1%
CVSS Severity
CVSS v3 Score 8.1
CVSS v2 Score 6.8
Proposed Action
Elasticsearch enables dynamic scripting, which allows remote attackers to execute arbitrary MVEL expressions and Java code.
Ransomware Campaign
Unknown
References
Products affected by CVE-2014-3120


Contact Us

Shodan ® - All rights reserved