Skip to content
COOEY

EXPOSURES › CVE-2014-3120

CVE-2014-3120

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2022-03-25 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2014-3120 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 75/100 rceexploited-in-wildunpatched

Elasticsearch's dynamic scripting feature allowed remote attackers to execute arbitrary MVEL and Java code, a flaw listed in CISA's KEV catalog.

The vulnerability in Elasticsearch's dynamic scripting enabled remote code execution, allowing attackers to run arbitrary MVEL expressions and Java code. DIB organizations must ensure Elasticsearch is patched and restricted from executing dynamic scripts to prevent compromise. This is a known, actively exploited vulnerability that should be treated as a high-priority remediation item.

Shame score — A known, actively exploited remote code execution flaw in a widely deployed search engine, indicating a failure to patch or restrict dangerous features.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Elasticsearch enables dynamic scripting, which allows remote attackers to execute arbitrary MVEL expressions and Java code.

AFFECTED FEDRAMP PRODUCTS · 1
PRODUCTSTATUS
Elastic Cloud
Elastic
Authorized