Maven package intelligence

org.elasticsearch:elasticsearch Known Exploited Vulnerabilities

Track evidence-backed exploitation affecting the Maven package org.elasticsearch:elasticsearch, including the gap beyond CISA KEV, confidence assessments, and sensor observations.

Total KEVs
2
Known exploited vulnerabilities affecting org.elasticsearch:elasticsearch
In CISA KEV
2
Records also listed in the official catalog
Beyond CISA KEV
0
Additional exploited vulnerabilities absent from CISA KEV
Sensor Observed
1
org.elasticsearch:elasticsearch KEV with sensor-observed exploitation activity

Review org.elasticsearch:elasticsearch exploitation against the versions you run

All two exploited org.elasticsearch:elasticsearch vulnerabilities tracked here are also listed in CISA KEV.

100%
Covered by CISA
0%
Beyond CISA

Attested org.elasticsearch:elasticsearch vulnerabilities

2 known exploited vulnerabilities affecting this package.

Vulnerability CISA KEV Added
CVE-2014-3120

The default configuration in Elasticsearch before 1.2 enables dynamic scripting, which allows remote attackers to execute arbitrary MVEL...

In CISA 25 Mar 2022
CVE-2015-1427

The Groovy scripting engine in Elasticsearch before 1.3.8 and 1.4.x before 1.4.3 allows remote attackers to bypass the sandbox protection mechanism...

In CISA 25 Mar 2022

Recurring weakness patterns

Improper Access Control account for mapped occurrences across this org.elasticsearch:elasticsearch KEV portfolio.

Browse all KEVs →