CVE Vulnerabilities

CVE-2015-1427

Published: Feb 17, 2015 | Modified: Oct 22, 2025
CVSS 3.x
9.8
CRITICAL
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
6.8 IMPORTANT
AV:N/AC:M/Au:N/C:P/I:P/A:P
RedHat/V3
6.5 IMPORTANT
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:L
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

The Groovy scripting engine in Elasticsearch before 1.3.8 and 1.4.x before 1.4.3 allows remote attackers to bypass the sandbox protection mechanism and execute arbitrary shell commands via a crafted script.

Affected Software

NameVendorStart VersionEnd Version
ElasticsearchElastic*1.3.8 (excluding)
ElasticsearchElastic1.4.0 (including)1.4.3 (excluding)
Red Hat JBoss A-MQ 6.3RedHat*
Red Hat JBoss Fuse 6.3RedHat*
ElasticsearchUbuntuartful*
ElasticsearchUbuntuupstream*
ElasticsearchUbuntuvivid*
ElasticsearchUbuntuwily*
ElasticsearchUbuntuyakkety*
ElasticsearchUbuntuzesty*

References