CVE-2015-1427
קריטית 9.8 מנוצלת בשטח (KEV)
ניצול פעיל מאומת — קטלוג CISA KEV
- שם
- Elasticsearch Groovy Scripting Engine Remote Code Execution Vulnerability
- נוסף לקטלוג
- יעד טיפול (פדרלי)
- פעולה נדרשת
- Apply updates per vendor instructions.
תיאור (מקור, אנגלית)
The Groovy scripting engine in Elasticsearch before 1.3.8 and 1.4.x before 1.4.3 allows remote attackers to bypass the sandbox protection mechanism and execute arbitrary shell commands via a crafted script.
מדדים
- CVSS 3.1
-
9.8 (CRITICAL)
מקור הציון: NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - EPSS — סבירות ניצול
- 100% (אחוזון 100) נכון ל-24/7/2026
מוצרים מושפעים
elastic: elasticsearch; redhat: fuse
קישורים
- http://www.elasticsearch.com/blog/elasticsearch-1-4-3-1-3-8-released/ PatchVendor Advisory
- https://www.elastic.co/community/security/ Not ApplicableVendor Advisory
- http://www.elasticsearch.com/blog/elasticsearch-1-4-3-1-3-8-released/ PatchVendor Advisory
- https://www.elastic.co/community/security/ Not ApplicableVendor Advisory
- http://packetstormsecurity.com/files/130784/ElasticSearch-Unauthenticated-Remo… ExploitThird Party AdvisoryVDB Entry
- http://packetstormsecurity.com/files/130784/ElasticSearch-Unauthenticated-Remo… ExploitThird Party AdvisoryVDB Entry
- http://packetstormsecurity.com/files/130368/Elasticsearch-1.3.7-1.4.2-Sandbox-… Third Party AdvisoryVDB Entry
- http://www.securityfocus.com/archive/1/534689/100/0/threaded Broken LinkThird Party AdvisoryVDB Entry
- http://www.securityfocus.com/bid/72585 Broken LinkThird Party AdvisoryVDB Entry
- https://access.redhat.com/errata/RHSA-2017:0868 Third Party Advisory