Skip to content
ElasticsearchGHSA-mrfm-jxgf-2h6v

Elasticsearch Improper Access Control vulnerability

High8.1CVE-2014-3120 · Published May 17, 2022 · updated Oct 22, 2025

The default configuration in Elasticsearch before 1.4.0.Beta1 enables dynamic scripting, which allows remote attackers to execute arbitrary MVEL expressions and Java code via the source parameter to _search. NOTE: this only violates the vendor's intended security policy if the user does not run Elasticsearch in its own independent virtual machine.

GitHub advisory

Affected versions

PackageAffectedFixed in
org.elasticsearch:elasticsearch
Maven
< 1.4.0.Beta11.4.0.Beta1
Details and references

More Elasticsearch advisories

All Elasticsearch
Advisory
Improper Limitation of a Pathname to a Restricted Directory in Elasticsearch
MediumMay 17, 2022
Cross-site scripting in Elasticsearch
MediumMay 14, 2022
Improper Access Control in Elasticsearch
HighMay 14, 2022
Improper Access Control in Elasticsearch
High7.5May 14, 2022
Improper Limitation of a Pathname to a Restricted Directory in Elasticsearch
MediumMay 14, 2022
Improper Restriction of XML External Entity Reference in Elasticsearch
Medium5.9May 13, 2022

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.