Mitel Forums - The Unofficial Source

Mitel Forums => Mitel Software Applications => Topic started by: marinacu on July 31, 2019, 10:13:49 AM

Title: Elasticsearch Groovy Script RCE
Post by: marinacu on July 31, 2019, 10:13:49 AM
Our mitel server is running an old ES version that has not been patched since it came out.  Our ES version [still] is Mitel's KB to fix this is to block port 9200 at the firewall; Even though ES realeased an updated, Mitel has not.  Our server is internal, so we're thinking to use the windows firewall.
Is there anyone else experiencing this?  how did you fix it?