The default configuration in Elasticsearch before 1.4.0.Beta1 enables dynamic scripting, which allows remote attackers to execute arbitrary MVEL expressions and Java code via the source parameter to _search. NOTE: this only violates the vendor's intended security policy if the user does not run Elasticsearch in its own independent virtual machine.
{ "github_reviewed_at": "2025-01-06T22:28:40Z", "cwe_ids": [ "CWE-284" ], "nvd_published_at": "2014-07-28T19:55:00Z", "severity": "MODERATE", "github_reviewed": true }