SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityAnalyzed

CVE-2014-3120

Elasticsearch Remote Code Execution Vulnerability

KEVHIGH 8.1EPSS 88.6%

Does this matter?

Known to be exploited in the wild (CISA KEV, CISA remediation deadline 15 April 2022). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.

Description

The default configuration in Elasticsearch before 1.2 enables dynamic scripting, which allows remote attackers to execute arbitrary MVEL expressions and Java code via the source parameter to _search. NOTE: this only violates the vendor's intended security policy if the user does not run Elasticsearch in its own independent virtual machine.

CVSS 3.1
8.1 HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
EPSS
88.56% probability · 100th percentile
CISA KEV
Listed 25 March 2022 · due 15 April 2022
Weakness
CWE-284
Affected
elastic/elasticsearch
Source
cve@mitre.org

CISA notes

Apply updates per vendor instructions. https://nvd.nist.gov/vuln/detail/CVE-2014-3120

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.