HIGH 8.1 Maven KEV

Elasticsearch Improper Access Control vulnerability

GHSA-mrfm-jxgf-2h6v · CVE-2014-3120

Published · Modified

AI SAST

Find this class of vulnerability in your own code

Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.

Description

The default configuration in Elasticsearch before 1.4.0.Beta1 enables dynamic scripting, which allows remote attackers to execute arbitrary MVEL expressions and Java code via the source parameter to _search. NOTE: this only violates the vendor's intended security policy if the user does not run Elasticsearch in its own independent virtual machine.

Ready to move

Start Securing

Free, no credit card | First findings in minutes