Back to list
Elasticsearch vulnerability CVE-2014-6439
Oct 02 2014 02:37PM
Jordan Sissel (jordan sissel elasticsearch com)
Elasticsearch versions 1.3.x and prior have a default configuration for
CORS that allows an attacker to craft links that could cause a userâ??s
browser to send requests to Elasticsearch instances on their local network.
These requests could cause data loss or compromise.
We have been assigned CVE-2014-6439 for this issue.
Version 1.4.0 beta 1 and later change the default configuration.
Users should either set â??http.cors.enabledâ? to false, or set
â??http.cors.allow-originâ? to the value of the server that should be allowed
access, such as localhost or a server hosting Kibana. Disabling CORS
entirely with the former setting is more secure, but may not be suitable
for all use cases.
Overall CVSS score: 5.3
[ reply ]
Copyright 2010, SecurityFocus