elasticsearch: remote code execution flaw via dynamic scripting
Published Jul 28, 2014 ·Due Apr 15, 2022
8.1
HIGHCVSS 3.1
EPSS 88.56%
Description
The default configuration in Elasticsearch before 1.2 enables dynamic scripting, which allows remote attackers to execute arbitrary MVEL expressions and Java code via the source parameter to _search. NOTE: this only violates the vendor's intended security policy if the user does not run Elasticsearch in its own independent virtual machine.
Affected products
No data.
- < 1.2.0
No data.
Fuse ESB Enterprise 7.1.0
n/a
Fixed · RHSA-2014:1171
Fuse MQ Enterprise 7.1.0
n/a
Fixed · RHSA-2014:1171
Fuse Management Console 7.1.0
n/a
Fixed · RHSA-2014:1171
Red Hat JBoss A-MQ 6.1
n/a
Fixed · RHSA-2014:1170
Red Hat JBoss Fuse 6.1
n/a
Fixed · RHSA-2014:1170
Red Hat Subscription Asset Manager 1.4
katello-configure-0:1.4.5.1-3.el6sam
Fixed · RHSA-2014:1186
Red Hat Satellite 6
elasticsearch
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Fuse ESB Enterprise 7.1.0 | n/a | Fixed | RHSA-2014:1171 |
| Fuse MQ Enterprise 7.1.0 | n/a | Fixed | RHSA-2014:1171 |
| Fuse Management Console 7.1.0 | n/a | Fixed | RHSA-2014:1171 |
| Red Hat JBoss A-MQ 6.1 | n/a | Fixed | RHSA-2014:1170 |
| Red Hat JBoss Fuse 6.1 | n/a | Fixed | RHSA-2014:1170 |
| Red Hat Subscription Asset Manager 1.4 | katello-configure-0:1.4.5.1-3.el6sam | Fixed | RHSA-2014:1186 |
| Red Hat Satellite 6 | elasticsearch | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
On Subscription Asset Manager (SAM) 1, the elasticsearch service is only bound to the loopback interface by default. To exploit this issue on a SAM 1 system, an attacker must have local access to the system. On Red Hat JBoss Fuse and Red Hat JBoss A-MQ, the elasticsearch service is only started if the insight-elasticsearch feature is installed. This feature is not installed by default.
References (21)
- http://bouk.co/blog/elasticsearch-rce x_refsource_MISCExploit
- http://www.exploit-db.com/exploits/33370 exploitx_refsource_EXPLOIT-DB
- http://www.osvdb.org/106949 vdb-entryx_refsource_OSVDBBroken Link
- http://www.rapid7.com/db/modules/exploit/multi/elasticsearch/script_mvel_rce x_refsource_MISCExploitThird Party Advisory
- http://www.securityfocus.com/bid/67731 vdb-entryx_refsource_BIDExploit
- https://access.redhat.com/security/cve/CVE-2014-3120 Vendor Advisory
- https://access.redhat.com/solutions/1191453
- https://bugzilla.redhat.com/show_bug.cgi?id=1124252 Issue Tracking
- https://github.com/advisories/GHSA-mrfm-jxgf-2h6v Advisory
- https://github.com/elastic/elasticsearch/commit/bd0eb32d9c3c3f5b6e5f8630c859cd04bdcd4e06
- https://github.com/elastic/elasticsearch/commit/f9de8b65898509e038e33215db0720b508477a12
- https://github.com/elastic/elasticsearch/issues/7151
- https://github.com/elastic/elasticsearch/pull/7642
- https://nvd.nist.gov/vuln/detail/CVE-2014-3120
- https://web.archive.org/web/20140813071419/http://www.securityfocus.com/bid/67731
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2014-3120 government-resourceUS Government Resource
- https://www.cve.org/CVERecord?id=CVE-2014-3120
- https://www.elastic.co/blog/logstash-1-4-3-released x_refsource_CONFIRMVendor Advisory
- https://www.elastic.co/community/security x_refsource_CONFIRMVendor Advisory
- https://www.found.no/foundation/elasticsearch-security/#staying-safe-while-developing-with-elasticsearch x_refsource_MISCExploit
Change history (0)
No recorded changes yet.