Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
8.1
CVE-2014-3120
- EPSS 88.56%
- Veröffentlicht 28.07.2014 19:55:04
- Zuletzt bearbeitet 22.04.2026 14:33:20
The default configuration in Elasticsearch before 1.2 enables dynamic scripting, which allows remote attackers to execute arbitrary MVEL expressions and Java code via the source parameter to _search. NOTE: this only violates the vendor's intended se...