Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2015-1427

Опубликовано: 11 фев. 2015
Источник: redhat
CVSS3: 6.5
CVSS2: 6.8
EPSS Критический

Описание

The Groovy scripting engine in Elasticsearch before 1.3.8 and 1.4.x before 1.4.3 allows remote attackers to bypass the sandbox protection mechanism and execute arbitrary shell commands via a crafted script.

It was reported that Elasticsearch versions 1.3.0-1.3.7 and 1.4.0-1.4.2 have vulnerabilities in the Groovy scripting engine. The vulnerability allows an attacker to construct Groovy scripts that escape the sandbox and execute shell commands as the user running the Elasticsearch Java VM.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat OpenShift Enterprise 2openshift-origin-cartridge-fuseNot affected
Red Hat Satellite 6elasticsearchNot affected
Red Hat Subscription Asset ManagerelasticsearchNot affected
Red Hat JBoss A-MQ 6.3FixedRHSA-2017:086803.04.2017
Red Hat JBoss Fuse 6.3FixedRHSA-2017:086803.04.2017

Показывать по

Дополнительная информация

Статус:

Important
https://bugzilla.redhat.com/show_bug.cgi?id=1191969elasticsearch: remote code execution via Groovy sandbox bypass

EPSS

Процентиль: 100%
0.99906
Критический

6.5 Medium

CVSS3

6.8 Medium

CVSS2

Связанные уязвимости

CVSS3: 9.8
ubuntu
больше 11 лет назад

The Groovy scripting engine in Elasticsearch before 1.3.8 and 1.4.x before 1.4.3 allows remote attackers to bypass the sandbox protection mechanism and execute arbitrary shell commands via a crafted script.

CVSS3: 9.8
nvd
больше 11 лет назад

The Groovy scripting engine in Elasticsearch before 1.3.8 and 1.4.x before 1.4.3 allows remote attackers to bypass the sandbox protection mechanism and execute arbitrary shell commands via a crafted script.

CVSS3: 9.8
debian
больше 11 лет назад

The Groovy scripting engine in Elasticsearch before 1.3.8 and 1.4.x be ...

github
больше 4 лет назад

Improper Access Control in Elasticsearch

EPSS

Процентиль: 100%
0.99906
Критический

6.5 Medium

CVSS3

6.8 Medium

CVSS2