Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-mrfm-jxgf-2h6v

Опубликовано: 17 мая 2022
Источник: github
Github: Прошло ревью
CVSS3: 8.1

Описание

Elasticsearch Improper Access Control vulnerability

The default configuration in Elasticsearch before 1.4.0.Beta1 enables dynamic scripting, which allows remote attackers to execute arbitrary MVEL expressions and Java code via the source parameter to _search. NOTE: this only violates the vendor's intended security policy if the user does not run Elasticsearch in its own independent virtual machine.

Пакеты

Наименование

org.elasticsearch:elasticsearch

maven
Затронутые версииВерсия исправления

< 1.4.0.Beta1

1.4.0.Beta1

EPSS

Процентиль: 99%
0.85557
Высокий

8.1 High

CVSS3

Дефекты

CWE-284

Связанные уязвимости

redhat
около 12 лет назад

The default configuration in Elasticsearch before 1.2 enables dynamic scripting, which allows remote attackers to execute arbitrary MVEL expressions and Java code via the source parameter to _search. NOTE: this only violates the vendor's intended security policy if the user does not run Elasticsearch in its own independent virtual machine.

CVSS3: 8.1
nvd
больше 11 лет назад

The default configuration in Elasticsearch before 1.2 enables dynamic scripting, which allows remote attackers to execute arbitrary MVEL expressions and Java code via the source parameter to _search. NOTE: this only violates the vendor's intended security policy if the user does not run Elasticsearch in its own independent virtual machine.

CVSS3: 8.1
debian
больше 11 лет назад

The default configuration in Elasticsearch before 1.2 enables dynamic ...

EPSS

Процентиль: 99%
0.85557
Высокий

8.1 High

CVSS3

Дефекты

CWE-284