Junglewise Threat Intelligence

CVE-2015-1427: Elasticsearch Groovy Scripting Engine Remote Code Execution Vulnerability

CVE-2015-1427 · Severity: critical · CVSS 9.8 · Exploited in the wild · Published 2022-03-25

Technologies: Elasticsearch. Vendors: Elastic.

Executive brief

The Groovy scripting engine in Elasticsearch allows remote attackers to bypass sandbox protection mechanisms and execute arbitrary shell commands via crafted scripts. This vulnerability stems from insufficient restriction of the Groovy environment, enabling unauthenticated remote code execution.

Affected products

  • Elasticsearch Elasticsearch before 1.3.8, 1.4.x before 1.4.3

Timeline

  • 2015-02-11: advisory: Vendor release of Elasticsearch 1.4.3 and 1.3.8 addressing the issue
  • 2022-03-25: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2022-03-25: disclosed: NVD publication date

Related threats