Junglewise Threat Intelligence

CVE-2014-3120: Elasticsearch Improper Access Control vulnerability

CVE-2014-3120 · Severity: critical · CVSS 3.1 · Exploited in the wild · Published 2022-05-17

Technologies: org.elasticsearch:elasticsearch (Maven), Elasticsearch. Vendors: Maven, Elastic.

Executive brief

The default configuration in Elasticsearch before version 1.2 enables dynamic scripting, allowing remote attackers to execute arbitrary MVEL expressions and Java code via the source parameter to _search. This vulnerability is exploited in the wild and is included in CISA's Known Exploited Vulnerabilities catalog.

Affected products

  • Elasticsearch Elasticsearch before 1.2.0

Timeline

  • 2014-07-28: disclosed: NVD Published Date
  • 2022-03-25: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2014-05-22: other: Exploit-DB entry published (approximate based on BID/OSVDB timing)

Related threats