CVE-2015-1427 Information
Feb 14, 2021
cve
Description
The Groovy scripting engine in Elasticsearch before 1.3.8 and 1.4.x before 1.4.3 allows remote attackers to bypass the sandbox protection mechanism and execute arbitrary shell commands via a crafted script.
Reference
http://packetstormsecurity.com/files/130368/Elasticsearch-1.3.7-1.4.2-Sandbox-Escape-Command-Execution.html http://packetstormsecurity.com/files/130784/ElasticSearch-Unauthenticated-Remote-Code-Execution.html http://www.elasticsearch.com/blog/elasticsearch-1-4-3-1-3-8-released/ http://www.securityfocus.com/archive/1/534689/100/0/threaded http://www.securityfocus.com/bid/72585 https://access.redhat.com/errata/RHSA-2017:0868 https://exchange.xforce.ibmcloud.com/vulnerabilities/100850 https://www.elastic.co/community/security/
Share on: