S4E just found a critical-severity finding from cve-2024-42009 scanner
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated Dec 16, 2023

CVE-2014-3120 Scanner

CVE-2014-3120 scanner - Remote Code Execution (RCE) vulnerability in Elasticsearch

Est. Time~15 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
2.9k
Times Used
continuous scan runs
3.5k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
🔴
CISA Known Exploited Vulnerability
This CVE is actively exploited in the wild. CISA mandates federal agencies to patch immediately.
CVECVE-2014-3120
8.1
CVSShigh
Exploitable remotely over the internet · low-privilege account sufficient.

The default configuration in Elasticsearch before 1.2 enables dynamic scripting, which allows remote attackers to execute arbitrary MVEL expressions and Java code via the source parameter to _search. NOTE: this only violates the vendor's intended security policy if the user does not run Elasticsearch in its own independent virtual machine.

Attack Vector
Network
Privileges Req.
Low
User Interaction
None
Affected
n/aby n/a
n/a
Updated Aug 21, 2026View on NVD →
Detail

Elasticsearch is a powerful open-source search engine and analytics tool used by many organizations to quickly and easily search, analyze, and visualize large amounts of data. It's primarily used to index and search large volumes of structured and unstructured data, such as logs, documents, and web data. It's also used to power various applications, including e-commerce websites, social media platforms, and enterprise search solutions.

However, despite its many benefits, Elasticsearch has been found to be vulnerable to a critical security flaw, known as CVE-2014-3120. This vulnerability allows remote attackers to execute arbitrary MVEL expressions and Java code via the source parameter to _search. This means that an attacker could gain access to confidential data, modify or delete data, or even take control of the server. This vulnerability was first discovered in 2014 and affected all versions of Elasticsearch before version 1.2.

If this vulnerability is exploited by a skilled attacker, it can have serious consequences for an organization. For example, an attacker could gain access to sensitive data such as user information, financial data, or trade secrets. They could modify or delete data, causing significant damage to an organization's operations and reputation. They could also use the compromised server to launch further attacks against other systems and networks.

In conclusion, Elasticsearch is a powerful tool used by many organizations to search and analyze large volumes of data. However, it is not immune to security vulnerabilities such as CVE-2014-3120. To protect against this vulnerability, organizations should take the necessary precautions, including upgrading to the latest version, disabling dynamic scripting, and implementing strict access controls. Thanks to the pro features of the s4e.io platform, organizations can easily and quickly learn about vulnerabilities in their digital assets, ensuring that they stay one step ahead of attackers.

 

REFERENCES

Solution Advice

To protect against this vulnerability, organizations can take several precautionary measures. These include:

  • Upgrading to the latest version of Elasticsearch, which includes a fix for the CVE-2014-3120 vulnerability.
  • Disabling dynamic scripting, which can be done by setting the "script.disable_dynamic" parameter to true in the Elasticsearch configuration file.
  • Implementing strict access controls and monitoring for any suspicious activity on the Elasticsearch server.
  • Regularly updating and patching all software and systems used in the organization to reduce the risk of vulnerabilities being exploited.
  • Conducting regular security audits and penetration testing to identify any vulnerabilities in the organization's digital assets.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2014-3120 scanner - Remote Code Execution (RCE) vulnerability in Elasticsearch | S4E