CVE-2015-1427
Elastic Elasticsearch
The Groovy scripting engine in Elasticsearch before 1.3.8 and 1.4.x before 1.4.3 allows remote attackers to bypass the sandbox protection mechanism and execute arbitrary shell commands via a crafted script.
- CVSS
- 9.8
- EPSS
- 99.9% 100.0% percentile
- CISA KEV
- Listed
- Published
- 2015.02.18