CVE-2014-3120
KEVHIGH 8.1EPSS 88.6%
The default configuration in Elasticsearch before 1.2 enables dynamic scripting, which allows remote attackers to execute arbitrary MVEL expressions and Java code via the source parameter to _search. NOTE: this only violates the vendor's intended security policy if the user does not run Elasticsearch in its own independent virtual machine.
- CVSS v3.1
- 8.1 HIGH
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N - CVSS v3.1
- 8.1 HIGH
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N - CVSS v3.1
- 8.1 HIGH
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N/E:H - CVSS v2.0
- 6.8 MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:P - EPSS
- 88.56% chance of exploitation in the next 30 days, 100th percentile
- CISA KEV
- added 2022-03-25
- Nuclei
- medium · CWE-284
- Published
- 2014-07-28
- Updated
- 2025-10-22
Proof-of-concept exploits (8)
- http://www.exploit-db.com/exploits/33370
- http://www.rapid7.com/db/modules/exploit/multi/elasticsearch/script_mvel_rce
- Olysyan/MSS0★ · 2021-12-31
- aazard/Cyber_Security_Base_Project_II0★ · 2025-06-11
- echohtp/ElasticSearch-CVE-2014-31206★ · 2014-07-07
- pi-2r/Elasticsearch-ExpLoit0★ · 2015-06-26
- xpgdgit/CVE-2014-31200★ · 2022-08-01
- Dungsocool/CVE-2014-3120
Nuclei templates (1)
Metasploit modules (1)
ExploitDB entries (2)
Vulhub environments (1)
Exploit collections (2)
- chaitin/xray/blob/master/pocs/elasticsearch-cve-2014-3120.yml
- zan8in/afrog/blob/main/pocs/afrog-pocs/CVE/2014/CVE-2014-3120.yaml