HTTP: Elastic Search Rest Arbitrary Code Execution

This signature detects attempts to exploit a known vulnerability against Elastic Search. A successful exploit can lead to buffer overflow and arbitrary code execution.

Extended Description

The default configuration in Elasticsearch before 1.2 enables dynamic scripting, which allows remote attackers to execute arbitrary MVEL expressions and Java code via the source parameter to _search. NOTE: this only violates the vendor's intended security policy if the user does not run Elasticsearch in its own independent virtual machine.

Affected Products

Elasticsearch elasticsearch

References

BugTraq: 67731

CVE: CVE-2014-3120

Short Name
HTTP:ELASTICSEARCH-REST-ACE
Severity
Minor
Recommended
False
Recommended Action
Drop
Category
HTTP
Keywords
Arbitrary CVE-2014-3120 Code Elastic Execution Rest Search bid:67731
Release Date
06/09/2015
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3761
False Positive
Unknown
Vendors

Elasticsearch

CVSS Score

6.8

Found a potential security threat?