Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2014-3120

Опубликовано: 09 дек. 2013
Источник: redhat
CVSS2: 6.8
EPSS Высокий

Описание

The default configuration in Elasticsearch before 1.2 enables dynamic scripting, which allows remote attackers to execute arbitrary MVEL expressions and Java code via the source parameter to _search. NOTE: this only violates the vendor's intended security policy if the user does not run Elasticsearch in its own independent virtual machine.

It was discovered that the default configuration of Elasticsearch enabled dynamic scripting, allowing a remote attacker to execute arbitrary MVEL expressions and Java code via the source parameter passed to _search.

Отчет

On Subscription Asset Manager (SAM) 1, the elasticsearch service is only bound to the loopback interface by default. To exploit this issue on a SAM 1 system, an attacker must have local access to the system. On Red Hat JBoss Fuse and Red Hat JBoss A-MQ, the elasticsearch service is only started if the insight-elasticsearch feature is installed. This feature is not installed by default.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat JBoss Enterprise Web Server 1amq-6Affected
Red Hat JBoss Enterprise Web Server 1fuse-6Affected
Red Hat JBoss Enterprise Web Server 1fuse-amq-7Affected
Red Hat JBoss Enterprise Web Server 1fuse-esb-7Affected
Red Hat Satellite 6elasticsearchNot affected
Fuse ESB Enterprise 7.1.0FixedRHSA-2014:117110.09.2014
Fuse Management Console 7.1.0FixedRHSA-2014:117110.09.2014
Fuse MQ Enterprise 7.1.0FixedRHSA-2014:117110.09.2014
Red Hat JBoss A-MQ 6.1FixedRHSA-2014:117010.09.2014
Red Hat JBoss Fuse 6.1FixedRHSA-2014:117010.09.2014

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-749
https://bugzilla.redhat.com/show_bug.cgi?id=1124252elasticsearch: remote code execution flaw via dynamic scripting

EPSS

Процентиль: 99%
0.85557
Высокий

6.8 Medium

CVSS2

Связанные уязвимости

CVSS3: 8.1
nvd
больше 11 лет назад

The default configuration in Elasticsearch before 1.2 enables dynamic scripting, which allows remote attackers to execute arbitrary MVEL expressions and Java code via the source parameter to _search. NOTE: this only violates the vendor's intended security policy if the user does not run Elasticsearch in its own independent virtual machine.

CVSS3: 8.1
debian
больше 11 лет назад

The default configuration in Elasticsearch before 1.2 enables dynamic ...

CVSS3: 8.1
github
больше 3 лет назад

Elasticsearch Improper Access Control vulnerability

EPSS

Процентиль: 99%
0.85557
Высокий

6.8 Medium

CVSS2