Vulnerability record · CVE-2014-3120 · published 28 July 2014
CVE-2014-3120: Elasticsearch dynamic scripting allows remote code execution
Elastic · Elasticsearch
The default configuration in Elasticsearch before 1.2 enables dynamic scripting, so the source parameter to _search can execute arbitrary MVEL expressions and Java code. This gives remote attackers a direct path to code execution on any instance left with default settings.
Description
The default configuration in Elasticsearch before 1.2 enables dynamic scripting, which allows remote attackers to execute arbitrary MVEL expressions and Java code via the source parameter to _search. NOTE: this only violates the vendor's intended security policy if the user does not run Elasticsearch in its own independent virtual machine.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Automated analysis
critical priorityIt is in CISA KEV with public exploit code and a very high EPSS score, and it yields remote code execution.
What it is
The default configuration in Elasticsearch before 1.2 enables dynamic scripting, so the source parameter to _search can execute arbitrary MVEL expressions and Java code. This gives remote attackers a direct path to code execution on any instance left with default settings.
Impact
An attacker can run arbitrary MVEL expressions and Java code on the Elasticsearch server, leading to full compromise of the host process and its data. The CVSS vector shows high confidentiality and integrity impact with no availability impact.
Attack surface
Reached over the network through the _search endpoint's source parameter; the CVSS vector requires low privileges (PR:L) and no user interaction (UI:N). The description notes the flaw only violates the vendor's intended security policy if Elasticsearch is not run in its own independent virtual machine.
Exploitation
CISA added this to KEV on 2022-03-25 with a due date of 2022-04-15, and EPSS shows a 30-day probability of 0.88559 (99.766th percentile). Multiple references are tagged Exploit, including Exploit-DB and a Rapid7 Metasploit module, so public exploit code exists.
What to do
- Upgrade Elasticsearch to 1.2 or later, where dynamic scripting is disabled by default.
- If upgrading is not immediately possible, disable dynamic scripting in the configuration.
- Restrict network access to the Elasticsearch HTTP/search port so only trusted hosts can reach it.
- Run Elasticsearch in an isolated environment or dedicated VM as the vendor intended.
- Review the cluster for unauthorized changes or unexpected processes.
Detection
- Monitor _search requests for a source parameter containing MVEL or Java code.
- Alert on Elasticsearch process spawning unexpected child processes or outbound connections.
- Audit Elasticsearch configuration for dynamic scripting being enabled.
- Check logs for anomalous search queries or errors tied to script execution.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2014-3120 to the Known Exploited Vulnerabilities catalog on 25 March 2022 as "Elasticsearch Remote Code Execution Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 15 April 2022.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2014-3120 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2014-3120), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.