Elasticsearch CVE-2014-3120 Arbitrary Java Code Execution Vulnerability
BID:67731
Info
Elasticsearch CVE-2014-3120 Arbitrary Java Code Execution Vulnerability
| Bugtraq ID: | 67731 |
| Class: | Input Validation Error |
| CVE: |
CVE-2014-3120 |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 09 2013 12:00AM |
| Updated: | Sep 15 2014 12:06AM |
| Credit: | Alex Brasetvik, Bouke van der Bijl |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
Elasticsearch CVE-2014-3120 Arbitrary Java Code Execution Vulnerability
Elasticsearch is prone to an arbitrary code-execution vulnerability.
An attacker could exploit this issue to execute arbitrary Java code in the context of the application.
Versions prior to ElasticSearch 1.2 are vulnerable.
Elasticsearch is prone to an arbitrary code-execution vulnerability.
An attacker could exploit this issue to execute arbitrary Java code in the context of the application.
Versions prior to ElasticSearch 1.2 are vulnerable.
Exploit / POC
Elasticsearch CVE-2014-3120 Arbitrary Java Code Execution Vulnerability
The following exploit codes are available:
The following exploit codes are available:
Solution / Fix
Elasticsearch CVE-2014-3120 Arbitrary Java Code Execution Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
Elasticsearch CVE-2014-3120 Arbitrary Java Code Execution Vulnerability
References:
References: