CVE-2014-3120 Scanner
CVE-2014-3120 scanner - Remote Code Execution (RCE) vulnerability in Elasticsearch
Used 2.9k times · 5.9k assets checked · url
The default configuration in Elasticsearch before 1.2 enables dynamic scripting, which allows remote attackers to execute arbitrary MVEL expressions and Java code via the source parameter to _search. NOTE: this only violates the vendor's intended security policy if the user does not run Elasticsearch in its own independent virtual machine.
CVE-2014-3120 scanner - Remote Code Execution (RCE) vulnerability in Elasticsearch
Used 2.9k times · 5.9k assets checked · url
S4E maps published CVEs to scanners and forecasts the next disclosure window for your stack.
Create a free account →