Back

HIGH KEV

elasticsearch: remote code execution flaw via dynamic scripting

Published Jul 28, 2014 ·Due Apr 15, 2022

Description

The default configuration in Elasticsearch before 1.2 enables dynamic scripting, which allows remote attackers to execute arbitrary MVEL expressions and Java code via the source parameter to _search. NOTE: this only violates the vendor's intended security policy if the user does not run Elasticsearch in its own independent virtual machine.

Affected products

Remediation

Red Hat statement

On Subscription Asset Manager (SAM) 1, the elasticsearch service is only bound to the loopback interface by default. To exploit this issue on a SAM 1 system, an attacker must have local access to the system. On Red Hat JBoss Fuse and Red Hat JBoss A-MQ, the elasticsearch service is only started if the insight-elasticsearch feature is installed. This feature is not installed by default.

Weaknesses (2)

References (21)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Jul 28, 2014
Updated Oct 22, 2025
Reserved Apr 29, 2014
CISA Vulnrichment
Updated Feb 10, 2025
NVD
Status Analyzed
Modified Jun 17, 2026
Red Hat
Severity Important
Public date Dec 9, 2013
GHSA-MRFM-JXGF-2H6V