CVE-2014-6439

medium
Published 2014-10-10 · Modified 2024-12-04
CVSS v3
CVSS v2
4.3
VIR risk
4.3

Description

Cross-site scripting in Elasticsearch

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: cve@mitre.org — https://www.elastic.co/community/security/

vendor Authored 2026-05-27

Vendor advisory: cve@mitre.org — http://www.elasticsearch.org/blog/elasticsearch-1-4-0-beta-released/

Package impact

EcosystemPackageVulnerableFixed
java Mavenorg.elasticsearch:elasticsearch<1.4.0.Beta11.4.0.Beta1

Application impact

VendorProductVersionsFixed
elasticsearchelasticsearch{"endIncluding":"1.3.3"}

References

CWEs

CWE-79

Verify integrity in audit chain (admin only). AS-IS.