← Global Threat Landscape

CVE-2014-3120

CWE-284

Critical

93.5

RPS

Description

The default configuration in Elasticsearch before 1.2 enables dynamic scripting, which allows remote attackers to execute arbitrary MVEL expressions and Java code via the source parameter to _search. NOTE: this only violates the vendor's intended security policy if the user does not run Elasticsearch in its own independent virtual machine.

Source: NVD

Signals

CVSS
8.1
High · v3.1
EPSS
88.55%
Probability of exploitation in the next 30 days (FIRST)
CISA KEV
In CISA KEV since Mar 2022
Fix commit
Fix commit known
Sources: MoreFixes, FreshFixes
Weakness
CWE-284
Published
28 Jul 2014
Last modified 22 Apr 2026

How to read these signals: RPS · EPSS · CISA KEV · Data sources

Get this score from the API

curl -H "Authorization: Bearer dsec_live_xxxxxxxx" \
  https://api.intelligence.devsecure.io/api/v1/rps/CVE-2014-3120

Replace the placeholder with your key. Get a free API key or rank your own CVEs.

Data as of 7 Oct 2026, 05:16 UK time

CVE-2014-3120 · RPS 93.5 · DevSecure Intelligence