Описание
The Groovy scripting engine in Elasticsearch before 1.3.8 and 1.4.x before 1.4.3 allows remote attackers to bypass the sandbox protection mechanism and execute arbitrary shell commands via a crafted script.
It was reported that Elasticsearch versions 1.3.0-1.3.7 and 1.4.0-1.4.2 have vulnerabilities in the Groovy scripting engine. The vulnerability allows an attacker to construct Groovy scripts that escape the sandbox and execute shell commands as the user running the Elasticsearch Java VM.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat JBoss Enterprise Web Server 1 | amq-6 | Not affected | ||
| Red Hat JBoss Enterprise Web Server 1 | fuse-6 | Not affected | ||
| Red Hat JBoss Enterprise Web Server 1 | fuse-amq-7 | Not affected | ||
| Red Hat JBoss Enterprise Web Server 1 | fuse-esb-7 | Not affected | ||
| Red Hat OpenShift Enterprise 2 | openshift-origin-cartridge-fuse | Not affected | ||
| Red Hat Satellite 6 | elasticsearch | Not affected | ||
| Red Hat Subscription Asset Manager | elasticsearch | Not affected | ||
| Red Hat JBoss A-MQ 6.3 | Fixed | RHSA-2017:0868 | 03.04.2017 | |
| Red Hat JBoss Fuse 6.3 | Fixed | RHSA-2017:0868 | 03.04.2017 |
Показывать по
Дополнительная информация
Статус:
6.5 Medium
CVSS3
6.8 Medium
CVSS2
Связанные уязвимости
The Groovy scripting engine in Elasticsearch before 1.3.8 and 1.4.x before 1.4.3 allows remote attackers to bypass the sandbox protection mechanism and execute arbitrary shell commands via a crafted script.
The Groovy scripting engine in Elasticsearch before 1.3.8 and 1.4.x before 1.4.3 allows remote attackers to bypass the sandbox protection mechanism and execute arbitrary shell commands via a crafted script.
The Groovy scripting engine in Elasticsearch before 1.3.8 and 1.4.x be ...
6.5 Medium
CVSS3
6.8 Medium
CVSS2