Executive brief
The default configuration in Elasticsearch before version 1.2 enables dynamic scripting, allowing remote attackers to execute arbitrary MVEL expressions and Java code via the source parameter to _search. This vulnerability is exploited in the wild and is included in CISA's Known Exploited Vulnerabilities catalog.
Affected products
- Elasticsearch Elasticsearch before 1.2.0
Timeline
- 2014-07-28: disclosed: NVD Published Date
- 2022-03-25: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2014-05-22: other: Exploit-DB entry published (approximate based on BID/OSVDB timing)