EXPOSURES › CVE-2014-3120
CVE-2014-3120
HIGH ⌖ ON CISA KEV · EXPLOITEDElasticsearch's dynamic scripting feature allowed remote attackers to execute arbitrary MVEL and Java code, a flaw listed in CISA's KEV catalog.
The vulnerability in Elasticsearch's dynamic scripting enabled remote code execution, allowing attackers to run arbitrary MVEL expressions and Java code. DIB organizations must ensure Elasticsearch is patched and restricted from executing dynamic scripts to prevent compromise. This is a known, actively exploited vulnerability that should be treated as a high-priority remediation item.
Shame score — A known, actively exploited remote code execution flaw in a widely deployed search engine, indicating a failure to patch or restrict dangerous features.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Elasticsearch enables dynamic scripting, which allows remote attackers to execute arbitrary MVEL expressions and Java code.
| PRODUCT | STATUS |
|---|---|
| Elastic Cloud Elastic |
Authorized |