Executive brief
The Groovy scripting engine in Elasticsearch allows remote attackers to bypass sandbox protection mechanisms and execute arbitrary shell commands via crafted scripts. This vulnerability stems from insufficient restriction of the Groovy environment, enabling unauthenticated remote code execution.
Affected products
- Elasticsearch Elasticsearch before 1.3.8, 1.4.x before 1.4.3
Timeline
- 2015-02-11: advisory: Vendor release of Elasticsearch 1.4.3 and 1.3.8 addressing the issue
- 2022-03-25: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2022-03-25: disclosed: NVD publication date