Vulnerability Description
The Groovy scripting engine in Elasticsearch before 1.3.8 and 1.4.x before 1.4.3 allows remote attackers to bypass the sandbox protection mechanism and execute arbitrary shell commands via a crafted script.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Elastic | Elasticsearch | < 1.3.8 |
| Redhat | Fuse | 1.0.0 |
References
- http://packetstormsecurity.com/files/130368/Elasticsearch-1.3.7-1.4.2-Sandbox-EsThird Party AdvisoryVDB Entry
- http://packetstormsecurity.com/files/130784/ElasticSearch-Unauthenticated-RemoteExploitThird Party AdvisoryVDB Entry
- http://www.elasticsearch.com/blog/elasticsearch-1-4-3-1-3-8-released/PatchVendor Advisory
- http://www.securityfocus.com/archive/1/534689/100/0/threadedBroken LinkThird Party AdvisoryVDB Entry
- http://www.securityfocus.com/bid/72585Broken LinkThird Party AdvisoryVDB Entry
- https://access.redhat.com/errata/RHSA-2017:0868Third Party Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/100850Third Party AdvisoryVDB Entry
- https://www.elastic.co/community/security/Not ApplicableVendor Advisory
- http://packetstormsecurity.com/files/130368/Elasticsearch-1.3.7-1.4.2-Sandbox-EsThird Party AdvisoryVDB Entry
- http://packetstormsecurity.com/files/130784/ElasticSearch-Unauthenticated-RemoteExploitThird Party AdvisoryVDB Entry
- http://www.elasticsearch.com/blog/elasticsearch-1-4-3-1-3-8-released/PatchVendor Advisory
- http://www.securityfocus.com/archive/1/534689/100/0/threadedBroken LinkThird Party AdvisoryVDB Entry
- http://www.securityfocus.com/bid/72585Broken LinkThird Party AdvisoryVDB Entry
- https://access.redhat.com/errata/RHSA-2017:0868Third Party Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/100850Third Party AdvisoryVDB Entry
FAQ
What is CVE-2015-1427?
CVE-2015-1427 is a vulnerability with a CVSS score of 9.8 (CRITICAL). The Groovy scripting engine in Elasticsearch before 1.3.8 and 1.4.x before 1.4.3 allows remote attackers to bypass the sandbox protection mechanism and execute arbitrary shell commands via a crafted s...
How severe is CVE-2015-1427?
CVE-2015-1427 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2015-1427?
Check the references section above for vendor advisories and patch information. Affected products include: Elastic Elasticsearch, Redhat Fuse.