Skip to content
COOEY

EXPOSURES › CVE-2015-1427

CVE-2015-1427

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2022-03-25 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2015-1427 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 75/100 rceexploited-in-wildunpatched

Elasticsearch's Groovy scripting engine allowed remote attackers to bypass sandbox protections and execute arbitrary shell commands.

The Groovy scripting engine in Elasticsearch lacked proper sandboxing, enabling remote code execution. DIB organizations must ensure Elasticsearch is patched and sandboxed to prevent attackers from executing arbitrary commands on their infrastructure.

Shame score — A known vulnerability in a widely used search engine allowed remote code execution, indicating a failure to adequately secure a critical component.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

The Groovy scripting engine in Elasticsearch allows remote attackers to bypass the sandbox protection mechanism and execute arbitrary shell commands.

AFFECTED FEDRAMP PRODUCTS · 1
PRODUCTSTATUS
Elastic Cloud
Elastic
Authorized