It was served through a proxy script, but actual ES instance was accessible to anyone and yes anyone could delete documents, groovy dynamic scripting was also enabled. Stupid setup I know... Our documents were not…
This is old. There are bots that scan servers for ES and try to exploit this vulnerability. Our servers were hacked through this hole before we upgraded to a newer version of ES. Now we don't allow remote access to ES…
It was served through a proxy script, but actual ES instance was accessible to anyone and yes anyone could delete documents, groovy dynamic scripting was also enabled. Stupid setup I know... Our documents were not…
This is old. There are bots that scan servers for ES and try to exploit this vulnerability. Our servers were hacked through this hole before we upgraded to a newer version of ES. Now we don't allow remote access to ES…