Логотип exploitDog
bind:CVE-2014-3120
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2014-3120

Количество 4

Количество 4

redhat логотип

CVE-2014-3120

около 12 лет назад

The default configuration in Elasticsearch before 1.2 enables dynamic scripting, which allows remote attackers to execute arbitrary MVEL expressions and Java code via the source parameter to _search. NOTE: this only violates the vendor's intended security policy if the user does not run Elasticsearch in its own independent virtual machine.

CVSS2: 6.8
EPSS: Высокий
nvd логотип

CVE-2014-3120

больше 11 лет назад

The default configuration in Elasticsearch before 1.2 enables dynamic scripting, which allows remote attackers to execute arbitrary MVEL expressions and Java code via the source parameter to _search. NOTE: this only violates the vendor's intended security policy if the user does not run Elasticsearch in its own independent virtual machine.

CVSS3: 8.1
EPSS: Высокий
debian логотип

CVE-2014-3120

больше 11 лет назад

The default configuration in Elasticsearch before 1.2 enables dynamic ...

CVSS3: 8.1
EPSS: Высокий
github логотип

GHSA-mrfm-jxgf-2h6v

больше 3 лет назад

Elasticsearch Improper Access Control vulnerability

CVSS3: 8.1
EPSS: Высокий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
redhat логотип
CVE-2014-3120

The default configuration in Elasticsearch before 1.2 enables dynamic scripting, which allows remote attackers to execute arbitrary MVEL expressions and Java code via the source parameter to _search. NOTE: this only violates the vendor's intended security policy if the user does not run Elasticsearch in its own independent virtual machine.

CVSS2: 6.8
86%
Высокий
около 12 лет назад
nvd логотип
CVE-2014-3120

The default configuration in Elasticsearch before 1.2 enables dynamic scripting, which allows remote attackers to execute arbitrary MVEL expressions and Java code via the source parameter to _search. NOTE: this only violates the vendor's intended security policy if the user does not run Elasticsearch in its own independent virtual machine.

CVSS3: 8.1
86%
Высокий
больше 11 лет назад
debian логотип
CVE-2014-3120

The default configuration in Elasticsearch before 1.2 enables dynamic ...

CVSS3: 8.1
86%
Высокий
больше 11 лет назад
github логотип
GHSA-mrfm-jxgf-2h6v

Elasticsearch Improper Access Control vulnerability

CVSS3: 8.1
86%
Высокий
больше 3 лет назад

Уязвимостей на страницу