Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2014-3120

Опубликовано: 28 июл. 2014
Источник: debian
EPSS Высокий

Описание

The default configuration in Elasticsearch before 1.2 enables dynamic scripting, which allows remote attackers to execute arbitrary MVEL expressions and Java code via the source parameter to _search. NOTE: this only violates the vendor's intended security policy if the user does not run Elasticsearch in its own independent virtual machine.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
elasticsearchfixed1.0.3+dfsg-3package

Примечания

  • https://github.com/elasticsearch/elasticsearch/commit/81e83cca

  • https://github.com/elasticsearch/elasticsearch/issues/5853

EPSS

Процентиль: 99%
0.85557
Высокий

Связанные уязвимости

redhat
около 12 лет назад

The default configuration in Elasticsearch before 1.2 enables dynamic scripting, which allows remote attackers to execute arbitrary MVEL expressions and Java code via the source parameter to _search. NOTE: this only violates the vendor's intended security policy if the user does not run Elasticsearch in its own independent virtual machine.

CVSS3: 8.1
nvd
больше 11 лет назад

The default configuration in Elasticsearch before 1.2 enables dynamic scripting, which allows remote attackers to execute arbitrary MVEL expressions and Java code via the source parameter to _search. NOTE: this only violates the vendor's intended security policy if the user does not run Elasticsearch in its own independent virtual machine.

CVSS3: 8.1
github
больше 3 лет назад

Elasticsearch Improper Access Control vulnerability

EPSS

Процентиль: 99%
0.85557
Высокий