CVE-2014-6439

EPSS 0.63%

Cross-site scripting in Elasticsearch

Published: 5/14/2022Modified: 12/4/2024

Description

Cross-site scripting (XSS) vulnerability in the CORS functionality in Elasticsearch before 1.4.0.Beta1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

Affected packages (1)

References (6)