Actively Exploited Vulnerabilities
Elasticsearch enables dynamic scripting, which allows remote attackers to execute arbitrary MVEL expressions and Java code.
Apply updates per vendor instructions.
CWE-284