← Back to browse · API

CVE-2014-3120

Severity
HIGH
CVSS
8.1
EPSS
0.88559
Risk score
88.4
CISA KEV
Yes
PoC
No
Published
2022-03-25
Modified
2022-03-25
First seen
2026-08-07
Aliases
EUVD-2022-5879, GHSA-MRFM-JXGF-2H6V
Products
Elastic:Elasticsearch, n/a:n/a n/a
Sources
euvd EUVD-2022-5879
cisa.gov CVE-2014-3120

Description

Elasticsearch enables dynamic scripting, which allows remote attackers to execute arbitrary MVEL expressions and Java code.

References