Umbra Wiki cve cve/CVE-2015-1427
Back to wiki

CVE-2015-1427 — Elasticsearch Groovy Scripting Engine Remote Code Execution Vulnerability

provenance: imported · CVE: CVE-2015-1427

CVE-2015-1427: Elasticsearch Groovy Scripting Engine Remote Code Execution Vulnerability

CISA Known Exploited Vulnerability (KEV)

Vendor / project Elastic
Product Elasticsearch
Date added 2022-03-25
Due date 2022-04-15
Ransomware campaign use Unknown

Description

The Groovy scripting engine in Elasticsearch allows remote attackers to bypass the sandbox protection mechanism and execute arbitrary shell commands.

Required action (CISA)

Apply updates per vendor instructions.

Notes

https://nvd.nist.gov/vuln/detail/CVE-2015-1427

References

  • NVD: https://nvd.nist.gov/vuln/detail/CVE-2015-1427
  • KEV catalog: https://www.cisa.gov/known-exploited-vulnerabilities-catalog