The Groovy scripting engine in Elasticsearch before 1.3.8 and 1.4.x before 1.4.3 allows remote attackers to bypass the sandbox protection mechanism and execute arbitrary shell commands via a crafted script.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Elasticsearch | Elastic | * | 1.3.8 (excluding) |
| Elasticsearch | Elastic | 1.4.0 (including) | 1.4.3 (excluding) |
| Red Hat JBoss A-MQ 6.3 | RedHat | * | |
| Red Hat JBoss Fuse 6.3 | RedHat | * | |
| Elasticsearch | Ubuntu | artful | * |
| Elasticsearch | Ubuntu | upstream | * |
| Elasticsearch | Ubuntu | vivid | * |
| Elasticsearch | Ubuntu | wily | * |
| Elasticsearch | Ubuntu | yakkety | * |
| Elasticsearch | Ubuntu | zesty | * |