Umbra Wiki cve cve/CVE-2014-3120
Back to wiki

CVE-2014-3120 — Elasticsearch Remote Code Execution Vulnerability

provenance: imported · CVE: CVE-2014-3120

CVE-2014-3120: Elasticsearch Remote Code Execution Vulnerability

CISA Known Exploited Vulnerability (KEV)

Vendor / project Elastic
Product Elasticsearch
Date added 2022-03-25
Due date 2022-04-15
Ransomware campaign use Unknown

Description

Elasticsearch enables dynamic scripting, which allows remote attackers to execute arbitrary MVEL expressions and Java code.

Required action (CISA)

Apply updates per vendor instructions.

Notes

https://nvd.nist.gov/vuln/detail/CVE-2014-3120

References

  • NVD: https://nvd.nist.gov/vuln/detail/CVE-2014-3120
  • KEV catalog: https://www.cisa.gov/known-exploited-vulnerabilities-catalog